Win32/Mebroot [Threat Name]

Detection created2008-01-15
World activity peak 2008-08-12 (0.54 %)
Short description

Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware. The trojan hides its presence in the system. It uses techniques common for rootkits.


The system is typically infected through a drive-by download while a compromised website is being browsed.

The dropper (malicious installation program) is executed after the web browser has been exploited.

Win32/Mebroot replaces the original MBR (Master Boot Record) of the hard disk drive with its own program code, as well as placing additional code to load and patch the following files:

  • ntldr
  • ntoskrnl.exe

This causes the trojan to be executed on every system start.

Information stealing

Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware.

Win32/PSW.Sinowal is a trojan that steals passwords and other sensitive information.

The trojan is able to log keystrokes. The trojan can send the information to a remote machine.

Other information

The trojan can download and execute a file from the Internet. It can be controlled remotely.

Threat Variants with Description

Threat Variant Name Date Added Threat Type
Win32/Mebroot 2008-01-15 trojan

