Sophos

Troj/PcClien-ID

Aliases
  • BackDoor-CKB
  • TROJ_AGENT.EAH
  • Win32/TrojanDropper.Agent.IL
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from November 2006 (4.11)
Protection available since 11 September 2006 10:23:38 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PcClien-ID is a backdoor Trojan which allows a remote intruder to gain access and control over the computer. Troj/PcClien-ID is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

When first run Troj/PcClien-ID copies itself to <Temp>\@BEde.exe and creates the following files:

<current folder>\<original filename>.doc
<Windows>\offitems.log
<System>\drivers\updjsjas.sys
<System>\updjsjas.dll
<System>\updjsjas.drv
<System>\updjsjas.log

The file updjsjas.sys is detected as Troj/Agent-BSL. The document file is clean, and is opened by the Trojan when the Trojan is first executed.

The file updjsjas.dll is registered as a service named "SENS". Registry entries are created or modified under:

HKLM\SYSTEM\CurrentControlSet\Services\SENS\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer