Sophos

Troj/PcClient-N

Aliases
  • Backdoor.Win32.PcClient.fg
  • BackDoor-CKB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 28 October 2005 10:01:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PcClient-N is a backdoor Trojan.

When Troj/PcClient-N is installed the following files are created:

<System>\Zrfkupza.d1l
<System>\drivers\Zrfkupza.sys

The file Zrfkupza.sys is detected as Troj/RKPort-Fam.

Troj/PcClient-N includes functionality to inject its code into SVCHOSTS.EXE.

In order to run automatically each time a user logs on, Troj/PcClient-N installs itself as a service named "Zrfkupza" and creates registry entries under the following branch:

HKLM\SYSTEM\CurrentControlSet\Services\Zrfkupza

Under Windows 9x systems, Troj/PcClient-N will set the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<Trojan base filename>
<System>\<Trojan filename>

Troj/PcClient-N may attempt to download and execute additional files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer