Sinowal/Mebroot Super Trojan

Taffycat

Crunchy Cat
Joined
Jun 1, 2006
Messages
12,831
Reaction score
1,067
This one looks like a tricky critter. Apparently, it can by-pass most security applications (although XP is said to be more vulnerable than Vista.) More info HERE.
 
After reading that I ran the Blacklight rootkit scanner just to be safe! :eek:

Good find TC :)
 
TC,

Great fine btw.


Ian, is the Blacklight rootkit scanner built into Kaspersky or do you have to download it off the net?

Edit, Found out in the infomation where to download it.

Thanks,

Wiz
 
Last edited:
Thank you for that link Ian - I've just downloaded that for XP, but do you think it would be a good idea to use it on Vista too please?
:)
 
Taffycat said:
Thank you for that link Ian - I've just downloaded that for XP, but do you think it would be a good idea to use it on Vista too please?
:)

Vista does have some extra protection against rootkits already, but there's no harm in running it :) It's one of the few rootkit detectors that works in Vista as far as I know :thumb:
 
Ian Cunningham said:
Vista does have some extra protection against rootkits already, but there's no harm in running it :) It's one of the few rootkit detectors that works in Vista as far as I know :thumb:

Thank you for your reply Ian - I thought I should check, just in case "Blacklight" was likely to clash with anything within Vista's gubbins ;)
 
I was round at a friends house today as they have been infected by this trojan. The only way they knew was a letter from the bank informing them that online banking had been cut off because they detected Sinowal access to her account. I've run everything I can think of, and nothing has detected it (HJT, Blacklight, Avira, SAS, Housecall, AVG etc...).

This little bugger is hard to find
wallbash.gif


FWIW, here is the followup article to the one above which explains how you might try to remove it:

http://windowssecrets.com/2008/11/26/03-Antivirus-tools-try-to-remove-Sinowal-Mebroot
 
Back
Top