Aliases
Backdoor.VB.gen
Type
Trojan
Description
Troj/Narhem-A is a keylogging Trojan.
Troj/Narhem-A copies itself to the following locations:
<Windows>\Reader.exe
<Windows>\Help\Mehran.exe
<Windows>\System\Mehran.exe
<Windows>\System32\Acrobat.exe
Troj/Narhem-A creates the following registry entries in order to run on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Acrobat
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Syscheck
Troj/Narhem-A logs keystrokes into C:\Syslog.dat and periodically emails this file to a predefined email address.
http://www.sophos.com/virusinfo/analyses/trojnarhema.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic