Reply
Bot Obliterator
Quads
Posts: 13,253
Registered: ‎07-21-2008

Beating Bootkits

I have been thinking of an idea to be able to have Norton beat Bootkits once detected.

 

Once Norton is installed on a computer and that system is clean, Norton can then be able to copy the Boot Sector of the machine it is installed on and hide it away within Norton for safe keeping (future use) if required.  Like a good Quarantine if you like and hidden.

 

Then in the future say that PC gets infected with a Bootkit like Tidserv, Mebroot, Alworo................. So "boot.xxxxxx"  Norton can then take that copy of the Boot Sector and overwrite the Bootkit with the original copy.  Now the MBR is clean. This also works or OEM versions (Dell, H.P., E Machines etc) as remember Norton has taken the copy from the machine it is installed on at a earlier date, so doesn't matter about being a OEM version.

 

It would also work for MBR Ransomware that locks the PC so the user can't get to Windows even loading.   Norton has the original copy stored away  So the user would be able to use the Recovery disc to access the stored copy in Norton on the Hard Drive and overwrite the MBR Ransomware (infected MBR). Restart the PC and Bingo Windows loads, no ransomware bootkit.

 

Quads

 

Stu Rootkit Eradicator
Rootkit Eradicator
Stu
Posts: 5,210
Registered: ‎04-08-2008

Re: Beating Bootkits

Very inter4esting theorie indeed.

Although I'm not sure this can be done

"All that we are is the result of what we have thought"
Bot Obliterator
Quads
Posts: 13,253
Registered: ‎07-21-2008

Re: Beating Bootkits

It can be done,  I can copy Boot Sectors with one click, not hard.

 

Quads

SendOfJive
Posts: 9,900
Kudos: 4,190
Solutions: 706
Registered: ‎02-07-2009

Re: Beating Bootkits

There are applications available that can back up the MBR, so it is certainly something that can be done.  It sounds like a very straightforward solution to a problem that is becoming much more common.  I think Quads' idea has a lot of merit.

Bot Obliterator
Quads
Posts: 13,253
Registered: ‎07-21-2008

Re: Beating Bootkits

Hmm, lets for now call it the "Good File Repository" that is a folder within Norton like other parts of Norton (Virus Defs etc.)

 

I had a question / statement saying about users accidently backing up a bad file or Boot Sector (which is a 512 byte file)

 

One way is to once Norton is installed on a system it is clean Norton will backup / Copy the required files and place them in the  "Good File Repository", after which the button (if one) and the copy function is disabled or greyed out, As Norton now has the legit copies it requires from the system in question.

This should stop both Norton and the User from accidently being played with by the click of a mouse and so on, hopefully meaning it's sucure.

 

Secondly, because the "Good File Repository" Folder is within Norton, it could be protected by Norton as part of the "Anti - Tamper Protection", this would be so hopefully  Malicous files or users can not delete the files or the whole Folder.

 

Quads

Regular Contributor
Topopurim47
Posts: 214
Registered: ‎02-21-2009

Re: Beating Bootkits

excellent idea.   along with some type of mbr guard

Contributor
kb14
Posts: 11
Registered: ‎06-05-2010

Re: Beating Bootkits

Great idea!

Contributor
The_Kid
Posts: 17
Registered: ‎07-20-2011

Re: Beating Bootkits

Great idea. I hope norton includes this.

Bot Obliterator
Quads
Posts: 13,253
Registered: ‎07-21-2008

Re: Beating Bootkits

One reason why Norton needs to find a way with Bootkits/ Rootkits, including OEM PC's

 

http://www.symantec.com/connect/blogs/are-mbr-infections-back-fashion

 

Quads

Gretar
Posts: 163
Kudos: 4
Registered: ‎08-26-2010

Re: Beating Bootkits

This is a good idea, even if Bootkits are not common today it is on the rise, so hopefully Norton will include this into product.