Antivirus and Security Software from Sophos

Sophos blogs

Troj/Mbroot-E

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 21 April 2009 19:31:07 (GMT)
Last updated 7 July 2009 18:52:29 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for disinfecting master boot record viruses that store the boot sector.

Troj/Mbroot-E can be disinfected from Windows using SAV32CLI or by using the Sophos Bootable Anti-Virus CD.

If disinfected from Windows, the rootkit may rewrite the infected MBR when the computer is shutdown or restarted.

The fixmbr utility in the Windows Recovery Console can also be used to restore the original MBR.

More Information


Troj/Mbroot-E is a malicious MBR loader installed by a member of the Troj/Sinowal family of rootkits.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer