Win32/Mebroot [Threat Name]
Detection created | 2008-01-15 |
World activity peak | 2008-08-12 (0.54 %) |
Short description
Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware. The trojan hides its presence in the system. It uses techniques common for rootkits.
Installation
The system is typically infected through a drive-by download while a compromised website is being browsed.
The dropper (malicious installation program) is executed after the web browser has been exploited.
Win32/Mebroot replaces the original MBR (Master Boot Record) of the hard disk drive with its own program code, as well as placing additional code to load and patch the following files:
- ntldr
- ntoskrnl.exe
This causes the trojan to be executed on every system start.
Information stealing
Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware.
Win32/PSW.Sinowal is a trojan that steals passwords and other sensitive information.
The trojan is able to log keystrokes. The trojan can send the information to a remote machine.
Other information
The trojan can download and execute a file from the Internet. It can be controlled remotely.
Threat Variants with Description
Threat Variant Name | Date Added | Threat Type | |
Win32/Mebroot | 2008-01-15 | trojan |