The bootkit is installed on the computer by a trojan downloader distributed from a Chinese adult site. Once executed, the rootkit makes a copy of the old MBR and replaces the sectors with its own code. It then uses hooks to replace the fips.sys system driver with a malicious one. MBR rootkits are notoriously hard to remove because they can control the system before antivirus programs start. Users are advised to avoid downloading executable files offered to them by websites without being requested.
Source: https://thehackernews.com/2011/04/new-chinese-mbr-rootkit-identified.html

