Mebroot Rootkit - New Variants more advanced and difficult to detect

Posted Tuesday, April 21, 2009 7:24 PM by hwaldron

Mebroot (StealthMBR) is one of the most advanced rootkits circulating.  New variants show even more advancements in hooking into the Windows OS kernel.  AV detection has emerged to detect, eradicate, and repair MBR damages.  Always use safe practices in handling media, files, and URLs. 

Mebroot Rootkit - New Variants more advanced and difficult to detect
http://www.avertlabs.com/research/blog/index.php/2009/04/19/stealthmbr-gets-a-makeover/
http://www.prevx.com/blog/120/MBR-rootkit-changes-itself-and-strikes-again.html

QUOTE: StealthMBR has arguably been dubbed as the stealthiest rootkit ever seen. The new variants are using even ‘deeper’ techniques to evade detection. Broadly speaking, they are hijacking kernel objects (device object) to filter out access to the master boot record and prevent detection and repair.

Comments

No Comments