Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2006 (4.11) |
| Protection available since | 11 September 2006 10:23:38 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/PcClien-ID is a backdoor Trojan which allows a remote intruder to gain access and control over the computer. Troj/PcClien-ID is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
When first run Troj/PcClien-ID copies itself to <Temp>\@BEde.exe and creates the following files:
<current folder>\<original filename>.doc
<Windows>\offitems.log
<System>\drivers\updjsjas.sys
<System>\updjsjas.dll
<System>\updjsjas.drv
<System>\updjsjas.log
The file updjsjas.sys is detected as Troj/Agent-BSL. The document file is clean, and is opened by the Trojan when the Trojan is first executed.
The file updjsjas.dll is registered as a service named "SENS". Registry entries are created or modified under:
HKLM\SYSTEM\CurrentControlSet\Services\SENS\
