Trojan.Rmnet compromises MBR and steals ftp-client passwords
Real-time threat news
June 16, 2011
Trojan.Rmnet gets onto computers through infected flash drives or upon launching infected executable files. In other words, it spreads like an ordinary virus, since it has the ability to self-replicate—copy itself without any user intervention. The Trojan horse infects exe,. dll,. scr,. html,. htm and in some cases doc and xls files and can create autorun.inf files on removable storage devices. Immediately after its launch the Trojan horse modifies the master boot record, registers Micorsoft Windows Service (it can work as a rootkit in the system), attempts to remove RapportMgmtService and adds several malicious modules into the system that appear in the Windows Task Manager as four entries named iexplore.exe.
The Trojan horse's main task is searching and stealing passwords stored by ftp-clients most popular with users such as Ghisler, WS FTP, CuteFTP, FlashFXP, FileZilla, Bullet Proof FTP. This information can later be exploited to carry out network attacks or to place various malicious objects on remote servers. At the very least, with this information, virus writers will be able to access data stored in user folders and files, delete or modify it. In addition, malicious modules of Trojan.Rmnet can monitor network traffic and function as a backdoor.
According to Doctor Web, the Trojan horse has been in the "Top" of identified threats for at least a month. To protect a system from Trojan.Rmnet users only need to conduct an express-scan of their systems with Dr.Web which will fix the compromised bootrecord, cure infected files and remove the malicious service automatically.

