Antivirus and Security Software from Sophos

Sophos blogs

Troj/PcClient-V

Aliases
  • Trojan-Dropper.Win32.Agent.yk
  • BackDoor-CKB.dr
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 December 2005 09:15:05 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PcClient-V is a Trojan for the Windows platform.

When first run Troj/PcClient-V copies itself to <Temp>\abs.exe and creates the following files:

<Temp>\Hacker.exe
<System>\Hacker.exe
<System>\Hacker.asf
<System>\Hacker.dfg

The Hacker.exe files are also detected as Troj/PcClient-V. The file Hacker.asf is detected as Troj/Agent-YK. The file Hacker.dfg is a clean config file.

Troj/PcClient-V may also drop clean log files to the Windows system folder with the filename <random number>.dat

The file Hacker.exe is registered as a system driver service named "Messenger" (repacing any existing services named "Messenger"). Registry entries are created or modified under:

HKLM\SYSTEM\CurrentControlSet\Services\Messenger\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer