View Full Version : Mebroot
rollers
January 13th, 2008, 04:49 AM
Now that the Mebroot rootkit has been around for a few days, (named by symantec) does anyone have any idea which other AV's recognise it? I guess the problem is that so many of them give the virus different names, AVG did not recognise it under mebroot when I tried it, so does it use a different name for it?
If anyone has any ideas's I would greatly appreciate it.
Thanks in advance, Rollers
plantextract
January 13th, 2008, 07:22 AM
Most AVs recognize it, AVG should see it as: PSW.Sinowal.C
RT
January 13th, 2008, 07:46 AM
Anyone know the Avast! name for it, please?
midway40
January 13th, 2008, 08:14 AM
McAfee identifies it as StealthMBR (http://vil.nai.com/vil/content/v_143908.htm) and StealthMBR!rootkit.
plantextract
January 13th, 2008, 10:55 AM
{QUOTE-> Anyone know the Avast! name for it, please? <-QUOTE}
last time i checked avast did not have a signature for it.
TaInTeD_SnIpEr
January 13th, 2008, 02:01 PM
Does anyone know what Kaspersky and ESET label this rootkit as?
plantextract
January 13th, 2008, 02:59 PM
{QUOTE-> Does anyone know what Kaspersky and ESET label this rootkit as? <-QUOTE}
kaspersky backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj (version 7/8 called it the first, the virustotal scanner the second name)
eset: Win32/Agent.DSJ
TaInTeD_SnIpEr
January 13th, 2008, 03:38 PM
{QUOTE-> kaspersky backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj (version 7/8 called it the first, the virustotal scanner the second name)
eset: Win32/Agent.DSJ <-QUOTE}
Alright, thank you.
sasa843
January 13th, 2008, 07:02 PM
And TrendMicro detect's it as TROJ_SINOWAL.AD
rollers
January 14th, 2008, 04:07 AM
Thanks for your answers.
Rollers
patrikr
January 14th, 2008, 09:57 AM
And F-Secure detect it as Trojan:W32/Mebroot.A
Patrik
Gizzy
January 15th, 2008, 02:59 AM
how about avira antivir PE premium?
ren
January 15th, 2008, 03:34 AM
Hello,
{QUOTE-> how about avira antivir PE premium? <-QUOTE}
# TR/PSW.Sinowal.GD
# TR/PWS.Sinowal.Gen
-ren
Gizzy
January 15th, 2008, 05:00 AM
{QUOTE-> Hello,
# TR/PSW.Sinowal.GD
# TR/PWS.Sinowal.Gen
-ren <-QUOTE}
Thank you :)
flyrfan111
January 15th, 2008, 07:30 AM
Anyone know what F-Prot detects it as?
SystemJunkie
February 26th, 2008, 12:26 PM
Does anyone know if HIPS or any other anti-keylogger can protect against the keylogging mechanism of StealthMBR?
Is anyone able to post a screen of the client/control console of this beast?
computer geek
February 26th, 2008, 01:06 PM
It would be a lot helpful if they decided on one name, instead of individual stupid random words.
C.S.J
February 26th, 2008, 01:57 PM
http://info.drweb.com/show/3257/en
& discussed here (http://www.wilderssecurity.com/showthread.php?t=198803)
vBulletin® Copyright ©2000-2008, Jelsoft Enterprises Ltd.