FANDOM


PCToaster is a dangerous memory resident trojan on Microsoft Windows that overwrites the MBR and wipes out the boot partition, usually System Reserved. It was intended for danooct1's Viewer-Made Malware contest, thus this trojan was not meant to be out in the wild.

PayloadsEdit

Viewer-Made Malware 9 - PCToaster (Win32)03:03

Viewer-Made Malware 9 - PCToaster (Win32)

Running PCToaster On Windows 802:36

Running PCToaster On Windows 8.0 RTM

When the program is executed, it asks the user for privileges via UAC. Then, a stock Java message box pops up saying that "This app cannot be used on "Windows 10" (on other versions of Windows, 10 is replaced with the system version, e.g. 8.1 or Vista)", and when the user presses the Exit button, the trojan tells the user that the button does not work. After this, VeryFun mounts the normally unenumerated boot partition (System Reserved on MBR systems) under V: and then deletes its contents to render Windows unbootable. PCToaster then terminates "lsass.exe", which causes the computer to schedule a reboot after 1 minute (this can be aborted by running "shutdown -a"). Afterwards, VeryFun unmounts every drive, including the primary partition C:, causing nearly every program to not work correctly, not work at all, or disappear altogether. Once the machine is reset, it fails to boot, as the MBR is overwritten with code displaying this message:

Hello there! I'm happy to tell that your PC has been TOASTED. 


extra crispy for your pleasure.


Thank you for using PCToaster

PCToaster is meant to be run on Windows 10. On Windows 8 and earlier, the virus still activates its payloads, but it will be unable to wipe out the boot partition and overwrite the MBR, but it can still terminate "lsass.exe" and eject all drives.

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.