User Tools

Site Tools


rootkit

Torpig/Sinowal/Mebroot

This has been around for awhile now, but I'm just getting around to looking into it. This moved up on my priority list with realizing a half dozen machines were infected. Basically, Mebroot is a rootkit that resides in the Master Boot Record (MBR) of the file system. This downloads the Torpig files that enable it to steal personal information.

Detection

This is easy to see when watching network traffic on another machine. Generally you will see a lot of DNS requests when idle. If the requests are going to DNS servers that you didn't specify and are for random looking, recently registered domains, you're probably infected.

Removal

rootkit.txt · Last modified: 2013/01/28 04:29 by 127.0.0.1