Sophos

Troj/Agent-EBK

Aliases
  • Backdoor.Win32.PcClient.tl
  • Backdoor.Win32.PcClient.pq
  • BackDoor-CKB.dr
  • New
  • Malware.u
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2007 (4.15)
Protection available since 1 February 2007 13:26:57 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-EBK is a keylogging Trojan with rootkit functionality.

When Troj/Agent-EBK is first installed, it creates the files

<System>\Ygyfrmrh.d1l
<System>\Ygyfrmrh.dll
<System>\Ygyfrmrh.sys

These files are also detected as Troj/Agent-EBK.

Ygyfrmrh.sys is installed as a system driver, providing stealth functionality in order to hide all three of the installed files.

Troj/Agent-EBK monitors keyboard activity and periodically sends all logged keypresses to a remote location via HTTP forms.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer