Troj/Inor-A is a backdoor Trojan that usually finds its way onto a user's system when a web page containing an encoded version of the executable is viewed.
Troj/Inor-A will create itself on the Desktop using the filename llass.exe, and add the following registy entries that point to this filename to ensure the Trojan gets executed at system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lar
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\lar
The following registry entry is also created:
HKLM\System\CurrentControlSet\Control\SLP
Troj/Inor-A has the ability to uninstall itself and change the port it is listening on via commands issued remotely.