Home Malware Programs Backdoors PcClient.BX

PcClient.BX

Posted: March 14, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 1,850
First Seen: March 14, 2011
Last Seen: April 4, 2023
OS(es) Affected: Windows

Aliases

Backdoor:Win32/PcClient.BX [Microsoft]Sus/UnkPack-C [Sophos]Heuristic.BehavesLike.Win32.Suspicious.H [McAfee-GW-Edition]TR/Crypt.XPACK.Gen [AntiVir]Trojan.DownLoad.14017 [DrWeb]Backdoor.Win32.PcClient.emgt [Kaspersky]Win32:Malware-gen [Avast]Trojan.Pandex [Symantec]W32/PcClient.R.gen!Eldorado [F-Prot]Win32/PcClient [NOD32]Backdoor [K7AntiVirus]generic!bg.fqj [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Windows NT\NET Frameuwork.exe File name: NET Frameuwork.exe
Size: 408.57 KB (408576 bytes)
MD5: 1a1ff1c3b4696b45f3c04147830f928e
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows NT
Group: Malware file
Last Updated: October 3, 2017
%PROGRAMFILES%\Windows NT\NET Frameuwork.exe File name: NET Frameuwork.exe
Size: 544.76 KB (544768 bytes)
MD5: 5f6f51a2da580edd08316d151817dc02
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows NT
Group: Malware file
Last Updated: October 3, 2017
%WINDIR%\SysWOW64\dgeeau.exe File name: dgeeau.exe
Size: 1.37 MB (1372160 bytes)
MD5: ece7275085b774610644e6891edc4f1b
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: January 9, 2017

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%windir%\System[RANDOM CHARACTERS].exeHKEY..\..\..\..{RegistryKeys}SYSTEM\ControlSet001\services\PCRatStactSYSTEM\ControlSet002\services\PCRatStactSYSTEM\CurrentControlSet\services\PCRatStact
Loading...