Viral Rewind: Virus.DOS.OneHalf

  Рет қаралды 487

MB Education

MB Education

10 ай бұрын

Visit my Linktree to access my socials and other channels: linktr.ee/mausolfb
-----------------------------------------------------------
. OneHalf is a virus that fascinated virus researchers in 1994 when it was first discovered. When loaded from an infected file, OneHalf infects the master boot record of the primary hard disk. Every time the computer boots with the infected MBR it will take the last two cylinders/sectors of the HDD and encrypt them using a XOR bitwise method. Then on the next boot it will encrypt the next two cylinders/sectors and repeat until it has encrypted half of the disk.
The infected MBR will also load OneHalf into memory on each boot thereby enabling it to infect .COM and .EXE files as they're accessed. It also employs stealth capabilities to both hide any file size changes and to decrypt any encrypted files as they're accessed to hide the infection from the user.
Payload: Upon reaching half of the disk being encrypted and the day is 4th, 8th, 10th, 14th, 18th, 20th, 24th, 28th and 30th of any month, OneHalf will halt the boot process with the following message:
" Dis is one half.
Press any key to continue..."
If a user accessed any encrypted files with a boot diskette or wrote a clean MBR over OneHalf's MBR they would not be able to access/read any of the files if they were located on the last half of the HDD. Files that were on the first half of the HDD will not be affected. Proper removal requires using a purpose-built tool to decrypt the last half of the HDD and then installing a clean MBR.
-----------------------------------------------
Like the Facebook page: / brian.mausolf
Follow me on Twitter: / mausolfb

Пікірлер: 1
@davipab
@davipab 10 ай бұрын
So it changes nothing to the person booting from the disk, but makes it harder for those mounting the disk externally to view the data... did this virus just invent BitLocker before BitLocker?
Viral Rewind: Virus.Win9x.Matrix
6:16
MB Education
Рет қаралды 302
Windows 10 Wont Boot, How To Fix Master Boot Record
21:17
CyberCPU Tech
Рет қаралды 183 М.
Finger Heart - Fancy Refill (Inside Out Animation)
00:30
FASH
Рет қаралды 21 МЛН
路飞太过分了,自己游泳。#海贼王#路飞
00:28
路飞与唐舞桐
Рет қаралды 22 МЛН
Warp6 SYS.LIST.UTIL
1:07
Scanjo
Рет қаралды 15
Virus.DOS.OneHalf
11:00
danooct1
Рет қаралды 222 М.
DOS Commands You Should Know
27:13
CyberCPU Tech
Рет қаралды 76 М.
License to Kill: Malware Hunting with the Sysinternals Tools
1:18:10
Mark Russinovich
Рет қаралды 78 М.
Borland Turbo Pascal 3.0 for CP/M 80 on MinZ SBC
13:38
MightyPEZ
Рет қаралды 617
These Keys Shouldn't Exist | Nostalgia Nerd
19:32
Nostalgia Nerd
Рет қаралды 652 М.
Virus.DOS.OlympicAIDS
8:13
danooct1
Рет қаралды 227 М.
Viral Rewind: Virus.DOS.Casino
9:05
MB Education
Рет қаралды 176
Data Recovery: Hard Drive Platter Swap in Our Lab!
36:05
Louis Rossmann
Рет қаралды 1,4 МЛН
What Does It Take To Run DOOM On A $10,000 IBM RS/6000 From 2001?
1:09:23
Красиво, но телефон жаль
0:32
Бесполезные Новости
Рет қаралды 1,6 МЛН
НЕ БЕРУ APPLE VISION PRO!
0:37
ТЕСЛЕР
Рет қаралды 363 М.
Облачная память в iPhone? #apple #iphone
0:53
Не шарю!
Рет қаралды 127 М.
Опасность фирменной зарядки Apple
0:57
SuperCrastan
Рет қаралды 9 МЛН
Лазер против камеры смартфона
1:01
Newtonlabs
Рет қаралды 717 М.