Look for these entries in your registry :
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run taskmgr.exe="%SYSTEM%\taskmgr.exe"
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\
CurrentVersion\Run taskmgr.exe=%SYSTEM%\taskmgr.exe"
If they are there, I am positive it is : TROJ_JUNTADOR.G
It is related to the following Backdoor : BKDR_MIMIC.T
And it does the following :
The Trojan, TROJ_JUNTADOR.G, installs this backdoor (BKDR_MIMIC.T) as an Internet Relay Chat (mIRC) client. Unauthorized remote users may access machines infected with this malware through mIRC channels and then use them to launch a Distributed Denial of Service (DDoS) attack.





Reply With Quote