Sophos

Troj/PcClien-AH

Aliases
  • Backdoor.Win32.PcClient.jx
  • Backdoor.Win32.PcClient.ik
  • W32/Pcclient.DB@bd
  • BackDoor-CKB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 20 January 2006 22:06:34 (GMT)
Last updated 18 July 2006 22:14:58 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PcClien-AH is a Trojan for the Windows platform.

Troj/PcClien-AH includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/PcClien-AH is installed the following files are created:

<Windows system folder>\drivers\pnezhftx.sys
<Windows system folder>\pnezhftx.dll

pnezhftx.sys is corrupt and can be removed safely. pnezhftx.dll is also detected as Troj/PcClien-AH.

Troj/PcClien-AH installs pnezhftx.sys as a service with the display name "pnezhftx". Several registry entries are created beneath the following location:

HKLM\SYSTEM\CurrentControlSet\Services\pnezhftx

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer