Troj/Inor-A

Category: Viruses and Spyware Protection available since:03 Oct 2003 00:00:00 (GMT)
Type: Trojan Last Updated:03 Oct 2003 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Inor-A is a backdoor Trojan that usually finds its way onto a user's system when a web page containing an encoded version of the executable is viewed.

Troj/Inor-A will create itself on the Desktop using the filename llass.exe, and add the following registy entries that point to this filename to ensure the Trojan gets executed at system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lar

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\lar

The following registry entry is also created:

HKLM\System\CurrentControlSet\Control\SLP

Troj/Inor-A has the ability to uninstall itself and change the port it is listening on via commands issued remotely.

download Try Sophos products for free
Download now