PDA

View Full Version : Mebroot


rollers
January 13th, 2008, 04:49 AM
Now that the Mebroot rootkit has been around for a few days, (named by symantec) does anyone have any idea which other AV's recognise it? I guess the problem is that so many of them give the virus different names, AVG did not recognise it under mebroot when I tried it, so does it use a different name for it?
If anyone has any ideas's I would greatly appreciate it.

Thanks in advance, Rollers

plantextract
January 13th, 2008, 07:22 AM
Most AVs recognize it, AVG should see it as: PSW.Sinowal.C

RT
January 13th, 2008, 07:46 AM
Anyone know the Avast! name for it, please?

midway40
January 13th, 2008, 08:14 AM
McAfee identifies it as StealthMBR (http://vil.nai.com/vil/content/v_143908.htm) and StealthMBR!rootkit.

plantextract
January 13th, 2008, 10:55 AM
{QUOTE-> Anyone know the Avast! name for it, please? <-QUOTE}
last time i checked avast did not have a signature for it.

TaInTeD_SnIpEr
January 13th, 2008, 02:01 PM
Does anyone know what Kaspersky and ESET label this rootkit as?

plantextract
January 13th, 2008, 02:59 PM
{QUOTE-> Does anyone know what Kaspersky and ESET label this rootkit as? <-QUOTE}
kaspersky backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj (version 7/8 called it the first, the virustotal scanner the second name)
eset: Win32/Agent.DSJ

TaInTeD_SnIpEr
January 13th, 2008, 03:38 PM
{QUOTE-> kaspersky backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj (version 7/8 called it the first, the virustotal scanner the second name)
eset: Win32/Agent.DSJ <-QUOTE}

Alright, thank you.

sasa843
January 13th, 2008, 07:02 PM
And TrendMicro detect's it as TROJ_SINOWAL.AD

rollers
January 14th, 2008, 04:07 AM
Thanks for your answers.

Rollers

patrikr
January 14th, 2008, 09:57 AM
And F-Secure detect it as Trojan:W32/Mebroot.A

Patrik

Gizzy
January 15th, 2008, 02:59 AM
how about avira antivir PE premium?

ren
January 15th, 2008, 03:34 AM
Hello,

{QUOTE-> how about avira antivir PE premium? <-QUOTE}
# TR/PSW.Sinowal.GD
# TR/PWS.Sinowal.Gen

-ren

Gizzy
January 15th, 2008, 05:00 AM
{QUOTE-> Hello,


# TR/PSW.Sinowal.GD
# TR/PWS.Sinowal.Gen

-ren <-QUOTE}

Thank you :)

flyrfan111
January 15th, 2008, 07:30 AM
Anyone know what F-Prot detects it as?

SystemJunkie
February 26th, 2008, 12:26 PM
Does anyone know if HIPS or any other anti-keylogger can protect against the keylogging mechanism of StealthMBR?

Is anyone able to post a screen of the client/control console of this beast?

computer geek
February 26th, 2008, 01:06 PM
It would be a lot helpful if they decided on one name, instead of individual stupid random words.

C.S.J
February 26th, 2008, 01:57 PM
http://info.drweb.com/show/3257/en

& discussed here (http://www.wilderssecurity.com/showthread.php?t=198803)