Sophos

Troj/PcClien-LZ

Aliases
  • Backdoor.Win32.PcClient.cnq
  • Backdoor:Win32/PcClient.DF
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 17 April 2008 22:53:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PcClien-LZ creates a file <System>\<random name>.dll which is also detected as Troj/PcClient-LZ.

Troj/PcClien-LZ registers itself as a service named "woibzi".

Troj/PcClien-LZ creates the following registry entries:

HKLM\SYSTEM\CurrentControlSet\Services\woibzi
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\woibzi
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WOIBZI

Corresponding keys are created for each control set in the registry.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer