The Mebroot Trojan is the first new trojan found in the wild, which modifies the MBR (Main Boot Record). This trojan is usually installed via drive-by downloads, reportedly from gfeptwe.com. Once inside, this parasite detects the active boot partition and infects the MBR. The original MBR is copied to sector 62 of the hard disk. Mebroot opens a backdoor for other attackers and hides itself using rootkit techniques.
The Mebroot Trojan is a threat and should be removed upon detection. Due to MBR-infection, Mebroot trojan acts as rootkit as well, thus detecting and removing the parasite manually is quite difficult task. Besides removing infected files, you will need to restore original boot record of the computer using windows install cd, which might corrupt your PC in some cases. This is done by a) booting your PC to rescue mode from windows install/recovery cd. b) executing “fdisk /mbr” to restore original master boot record. c) booting into safe mode and deleting mebroots dlls.
Automatic Malware removal tools