Mebroot

Discussion in 'other anti-virus software' started by rollers, Jan 13, 2008.

Thread Status:
Not open for further replies.
  1. rollers

    rollers Registered Member

    Now that the Mebroot rootkit has been around for a few days, (named by symantec) does anyone have any idea which other AV's recognise it? I guess the problem is that so many of them give the virus different names, AVG did not recognise it under mebroot when I tried it, so does it use a different name for it?
    If anyone has any ideas's I would greatly appreciate it.

    Thanks in advance, Rollers
     
  2. plantextract

    plantextract Registered Member

    Most AVs recognize it, AVG should see it as: PSW.Sinowal.C
     
  3. RT

    RT Registered Member

    Anyone know the Avast! name for it, please?
     
  4. midway40

    midway40 Registered Member

    McAfee identifies it as StealthMBR and StealthMBR!rootkit.
     
  5. plantextract

    plantextract Registered Member

    last time i checked avast did not have a signature for it.
     
  6. TaInTeD_SnIpEr

    TaInTeD_SnIpEr Registered Member

    Does anyone know what Kaspersky and ESET label this rootkit as?
     
  7. plantextract

    plantextract Registered Member

    kaspersky backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj (version 7/8 called it the first, the virustotal scanner the second name)
    eset: Win32/Agent.DSJ
     
  8. TaInTeD_SnIpEr

    TaInTeD_SnIpEr Registered Member

    Alright, thank you.
     
  9. sasa843

    sasa843 Registered Member

    And TrendMicro detect's it as TROJ_SINOWAL.AD
     
  10. rollers

    rollers Registered Member

    Thanks for your answers.

    Rollers
     
  11. patrikr

    patrikr AV Expert

    And F-Secure detect it as Trojan:W32/Mebroot.A

    Patrik
     
  12. Gizzy

    Gizzy Registered Member

    how about avira antivir PE premium?
     
  13. ren

    ren Registered Member

    Hello,

    # TR/PSW.Sinowal.GD
    # TR/PWS.Sinowal.Gen

    -ren
     
  14. Gizzy

    Gizzy Registered Member

    Thank you :)
     
  15. flyrfan111

    flyrfan111 Registered Member

    Anyone know what F-Prot detects it as?
     
  16. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Does anyone know if HIPS or any other anti-keylogger can protect against the keylogging mechanism of StealthMBR?

    Is anyone able to post a screen of the client/control console of this beast?
     
  17. computer geek

    computer geek Registered Member

    It would be a lot helpful if they decided on one name, instead of individual stupid random words.
     
  18. C.S.J

    C.S.J Massive Poster

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice