Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 16 September 2004 13:08:42 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mtron-B is a backdoor Trojan designed to steal online banking information.
The Trojan copies itself to MSWinSrv32.exe in the Windows system folder and adds the registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MSWinSrv32 = %Windows system%\MSWinSrv32.exe
Troj/Mtron-B monitors keystrokes in Windows that have titles including Netbenefits, Fidelity, e-gold, Citibank or Citi. The Trojan also deletes cookies and can act as a SOCKS proxy server.
Troj/Mtron-B can be controlled by a remote attacker via IRC.
