EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium

A security analyst is investigating a persistent infection on several Windows workstations. The malware appears to execute every time the system starts, even after attempts to remove it using standard antivirus software. Further analysis reveals that the malware has modified the system's boot records to ensure its continuous execution. Which type of malware is most likely responsible for this behavior?

  1. ARansomware
  2. BAdware
  3. CSpyware
  4. DBootkit
Show answer & explanation

Correct answer: D. Bootkit

A bootkit is a type of malware that infects the Master Boot Record (MBR) or Volume Boot Record (VBR) of a system. This allows it to load before the operating system, making it very difficult to detect and remove with traditional antivirus solutions, and ensuring persistence.

Why the other options are wrong

  • A. Ransomware encrypts data and demands a ransom, but its primary mechanism isn't boot record modification for persistence.
  • B. Adware displays unwanted advertisements and does not typically modify boot records for persistence.
  • C. Spyware collects information about the user without their knowledge but doesn't primarily focus on boot persistence.

Bootkit

A malicious program that modifies the boot sector or Master Boot Record (MBR) of a hard drive, allowing it to load before the operating system and hide its presence.

  • Infects the boot process (MBR/VBR)
  • Loads before the operating system
  • Difficult to detect and remove

Memory trick: Boot kits hide deep, ensuring they always greet the machine's first breath.

More Malware Threats questions