Troj/Hackarmy-A is an IRC backdoor Trojan that copies itself into the Windows system folder as win32server.scr or win32server.exe and sets the registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Winsock32driver = wn32server.scr
or
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Winsock32driver = win32server.exe
The Trojan then logs on to a predefined IRC server and waits for backdoor commands.