Sophos

Troj/Mutin-C

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from September 2004 (3.85)
Protection available since 12 July 2004 08:16:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mutin-C is an adware related IRC based backdoor trojan.

The trojan will attempt to run as a backgroud service with the name 'lanmanserver' by setting various registry entries under the name:
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\

It will then drop numerous files under the system32 directory, including utilities for backdoor usage such as:
Libparse.ex (PrcView)
bootdrv.dl (MotherboardMonitor)
firedaemon.ex (FireDaemon)
moo.dl (MotherboardMonitor)
psexec.ex (RemAdm-ProcLaunch)
rconnect.ex (SlimFTP)
setups.ex (Iroffer)
vbsystem35.ex (HideExec)
winutil32.ex (ServU-Daemon)
msvbrun.exe (mIRC 6.03)

UNR.EX (Troj/DarkSha-C)
spoolscvf.ex (Troj/IPCScan-A)

It also drops various config files required for these utilities under:
<system32>/networks
<system32>/logs
<system32>/bacra

It will then attempt to startup a backdoor server on a specific IRC server and wait for backdoor connections. It may allow anybody logging on to the backdoor server to upload/download any files and remotely execute them.

It will also attempt to disable the administrative share by setting the following parameters:
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\parameters\
AutoshareWks
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\parameters\
AutoShareServer

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer