Trojan.Rmnet compromises MBR and steals ftp-client passwords

Real-time threat news

June 16, 2011

Doctor Web warns users about a new modification of already-known Win32.Rmnet malware, capable of infecting the master boot record (MBR). With the MBR compromised Trojan.Rmnet starts before an anti-virus installed on a computer, which greatly complicates its detection and neutralization. The main purpose of this Trojan horse is stealing passwords saved in the system by popular ftp-clients.

Trojan.Rmnet gets onto computers through infected flash drives or upon launching infected executable files. In other words, it spreads like an ordinary virus, since it has the ability to self-replicate—copy itself without any user intervention. The Trojan horse infects exe,. dll,. scr,. html,. htm and in some cases doc and xls files and can create autorun.inf files on removable storage devices. Immediately after its launch the Trojan horse modifies the master boot record, registers Micorsoft Windows Service (it can work as a rootkit in the system), attempts to remove RapportMgmtService and adds several malicious modules into the system that appear in the Windows Task Manager as four entries named iexplore.exe.

The Trojan horse's main task is searching and stealing passwords stored by ftp-clients most popular with users such as Ghisler, WS FTP, CuteFTP, FlashFXP, FileZilla, Bullet Proof FTP. This information can later be exploited to carry out network attacks or to place various malicious objects on remote servers. At the very least, with this information, virus writers will be able to access data stored in user folders and files, delete or modify it. In addition, malicious modules of Trojan.Rmnet can monitor network traffic and function as a backdoor.

According to Doctor Web, the Trojan horse has been in the "Top" of identified threats for at least a month. To protect a system from Trojan.Rmnet users only need to conduct an express-scan of their systems with Dr.Web which will fix the compromised bootrecord, cure infected files and remove the malicious service automatically.

0
Latest All news