Save the bootstrap loader code elsewhere on disk,
replace it with virus startup code, leave PT entries
alone
2. Overwrite bootstrap loader code without saving it,
leave PT entries alone
3. Change only the PT entries (to point to virus code),
leave the bootstrap loader alone
4. Save entire MBR (loader and PT) to end of disk,
replace with virus version
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
TrendMicroDLPSSucks
11 months ago