Sophos

Troj/Mtron-B

Aliases
  • Backdoor.MTBot.b
  • IRC-Mtron
  • trojan
  • Win32/MTBot.B
  • trojan
  • Backdoor.Mtron
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 16 September 2004 13:08:42 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mtron-B is a backdoor Trojan designed to steal online banking information.

The Trojan copies itself to MSWinSrv32.exe in the Windows system folder and adds the registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MSWinSrv32 = %Windows system%\MSWinSrv32.exe

Troj/Mtron-B monitors keystrokes in Windows that have titles including Netbenefits, Fidelity, e-gold, Citibank or Citi. The Trojan also deletes cookies and can act as a SOCKS proxy server.

Troj/Mtron-B can be controlled by a remote attacker via IRC.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer