Sophos

Troj/PcClien-LF

Aliases
  • Backdoor.Win32.PcClient.axs
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 7 February 2008 17:14:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PcClien-LF is a Trojan for the Windows platform.

When Troj/PcClien-LF is installed the following files are created:

<System>\0005d2a5.log
<System>\drivers\jvymep.sys (also detected as Troj/PcClien-LF)
<System>\jvymep.dll (also detected as Troj/PcClien-LF)

The file jvymep.dll is registered as a new service named "cyxmgv". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\cyxmgv

The file jvymep.sys is registered as a new system driver service named "yyxmgvcz", with a display name of "yyxmgvcz" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\yyxmgvcz

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer