Summary

Summary
Action
More Information
| Included in our products from | September 2004 (3.85) |
|---|---|
| Protection available since | 12 July 2004 08:16:45 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mutin-C is an adware related IRC based backdoor trojan.
The trojan will attempt to run as a backgroud service with the name 'lanmanserver' by setting various registry entries under the name:
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\
It will then drop numerous files under the system32 directory, including utilities for backdoor usage such as:
Libparse.ex (PrcView)
bootdrv.dl (MotherboardMonitor)
firedaemon.ex (FireDaemon)
moo.dl (MotherboardMonitor)
psexec.ex (RemAdm-ProcLaunch)
rconnect.ex (SlimFTP)
setups.ex (Iroffer)
vbsystem35.ex (HideExec)
winutil32.ex (ServU-Daemon)
msvbrun.exe (mIRC 6.03)
UNR.EX (Troj/DarkSha-C)
spoolscvf.ex (Troj/IPCScan-A)
It also drops various config files required for these utilities under:
<system32>/networks
<system32>/logs
<system32>/bacra
It will then attempt to startup a backdoor server on a specific IRC server and wait for backdoor connections. It may allow anybody logging on to the backdoor server to upload/download any files and remotely execute them.
It will also attempt to disable the administrative share by setting the following parameters:
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\parameters\
AutoshareWks
HKLM\SOFTWARE\system\Currentcontrolset\Services\lanmanserver\parameters\
AutoShareServer
