Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Win32/Mebroot


You can download the removal tool here .
Short description
Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware. The trojan hides its presence in the system. It uses techniques common for rootkits.
Installation
The system is typically infected through a drive-by download while a compromised website is being browsed.

The dropper (malicious installation program) is executed after the web browser has been exploited.

Win32/Mebroot replaces the original MBR (Master Boot Record) of the hard disk drive with its own program code, as well as placing additional code to load and patch the following files:
  • ntoskrnl.exe
Information stealing
Win32/Mebroot is a trojan that installs Win32/PSW.Sinowal malware.

Win32/PSW.Sinowal is a trojan that steals passwords and other sensitive information.

The trojan is able to log keystrokes. The trojan can send the information to a remote machine.
Other information
The trojan can download and execute a file from the Internet. It can be controlled remotely.