one of my server virus has found name(StealthMBR.a Trojan). pls confirm this virus is critical?
How to remove it?
guide me that step where server not require to restart.
pls reply.
Hello,
StealthMBR (Mcafee) aka Trojan.Mebroot (Symantec) is a Trojan horse that modifies the Master Boot Record (MBR). It uses sophisticated rootkit techniques to hide its presence and opens a back door that allows a remote attacker control over the compromised computer.
Check this Article:
http://www.symantec.com/security_response/writeup.jsp?docid=2008-010718-3448-99
Trojan.Mebroot - Removal
http://www.symantec.com/security_response/writeup.jsp?docid=2008-010718-3448-99&tabid=3
Hope that helps!!
thanks mithun for reply, but i have one question. is restart required under the scanning?
any manually way to clear out this trojan because it attack on Server..
Upon scanning the machine, if the file is attached to some process, it may require you to Restart the machine.
MBR type viruses can be a problem. You have to reboot to remove it. MBR = Master Boot Record
Looks like we have a new MBR infection in the wild.
Boot.Xpaj.B is a detection for a Master Boot Record (MBR) infected by W32.Xpaj.B.
http://www.symantec.com/security_response/writeup.jsp?docid=2012-042517-0047-99
Thanks mithun issue is close now.
thank for great support
This new blog post may be of interest to followers of this thread:
W32.Xpaj.B is a File Infector with a Vengeance https://www-secure.symantec.com/connect/blogs/w32xpajb-file-infector-vengeance
Please take measures to ensure the safety of your networks, everybody........