Sophos

Troj/Narnar

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2000 (3.34)
Detected by All Sophos products

More Information

This backdoor Trojan installs itself in the Windows system folder with the filename tskmngr.exe, and changes the registry in such a way that the Trojan is run every time Windows is restarted.

The Trojan contains a simplified IRC client which, on every subsequent restart of Windows, uses the computer's internet connection to announce itself on a specific IRC channel on irc.dal.net. This allows other people with the client software to access infected users' computers.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer