|
|
|  |
|
|
|
|
F-Secure Trojan Information Pages: PcClient.VK

|
|
|
| Radar |
 |
|
|
|
Summary
|
| PcClient.VK, a variant of PcClient, is a Trojan. PcClient.VK attempts to hide processes, files, registry data and network connections and allows the attacker to perform arbitrary actions on the infected machine. PcClient.VK has a rootkit functionality and steals sensitive information from an infected computer. |
|
|
|
Disinfection
|
Detection and Disinfection of Rootkits
If the rootkit is not detected or it is hidden so that FSAV cannot detect its file, it is still possible to detect the malicious activity by scanning the system with generic rootkit scanner, such as F-Secure BlackLight. More information about F-Secure BlackLight Rootkit Elimination Technology can be found here:
http://www.f-secure.com/blacklight/
The BlackLight utility is also able to disinfect computers that are infected by rootkits. F-Secure Internet Security 2006/2007 include the BlackLight engine. |
|
|
|
Detailed Description
|
PcClient.VK is seen in the wild as the payload file installed on a host machine by a specially crafted Microsoft PowerPoint file that contains exploit code.
Once execution of PcClient.VK been initiated, its executable component will drop the following hard-coded files in the Windows System directory:
- Ybrcuugm.d1l - Backdoor
- Ybrcuugm.dll - Keylogger
Note: the file size of Ybrcuugm.d1l might vary due to garbage code appended at the end of the file.
It will also drop the following driver that will communicate with the dll files in order to hide the malware's processes, registry entries and files:
- %sysdir%\drivers\Ybrcuugm.sys
Moreover it also hides some network traffic that the PcClient.VK uses.
It modifies the following known registry entry as its autostart technique:
Data before:
- [HKLM\SYSTEM\CurrentControlSet\Services\dmserver\Parameters]
ServiceDll = %sysdir%\dmserver.dll
Data after:
- [HKLM\SYSTEM\CurrentControlSet\Services\dmserver\Parameters]
ServiceDll = %sysdir%\Ybrcuugm.d1l
In order for the system to work normally, Ybrcuugm.dll will execute its malicious routine and then pass the correct parameter to the original dmserver.dll.
It also adds the following autostart registry entry for the driver:
- [HKLM\System\ControlSet001\Services\Ybrcuugm]
ImagePath= C:\WINDOWS\system32\drivers\Ybrcuugm.sys
Note: This rootkit can be detected by F-Secure's BlackLight.
Part of its payload is that is logs all the keystrokes made by the user and saves it to the following file:
It then sends this file to a remote hacker.
Another part of the payload is that it has a backdoor component. The backdoor routine is injected into svchost.exe, which is capable doing the following:
- updating itself
- remote execution
This malware connects to the following site:
- http://baas.8866.org/[BLOCKED]ex.asp
|
|
|
|
Detection
|
F-Secure Anti-Virus detects this malware with the following updates: [FSAV_Database_Version] Version = 2006-09-29_02.
|
|
|
|
F-Secure Corporation |
|
|
|
|
|
Last Modified: October 03, 2006
|
|
|
|
|