Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2005 (3.99) |
| Protection available since | 1 October 2005 15:54:09 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Digarix-D is an IRC backdoor Trojan.
The Trojan usually arrives as a self extracting EXE archive that drops several files, the majority of which are legitimate utilities.
The file CODER.SUS contains most of the functionality of the Trojan.
Troj/Digarix-D uses a standard mIRC client to connect to a remote IRC server and listen for the commands from the Trojan writer.
The Trojan may create the following registry value:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NTupdater
to point to the renamed mIRC client.
