Threat description


Category: Malware
Type: Backdoor, Trojan
Platform: W32
Date Discovered: September 29, 2006


PcClient.VK, a variant of PcClient, is a Trojan. PcClient.VK attempts to hide processes, files, registry data and network connections and allows the attacker to perform arbitrary actions on the infected machine. PcClient.VK has a rootkit functionality and steals sensitive information from an infected computer.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

PcClient.VK is seen in the wild as the payload file installed on a host machine by a specially crafted Microsoft PowerPoint file that contains exploit code.

Once execution of PcClient.VK been initiated, its executable component will drop the following hard-coded files in the Windows System directory:

  • Ybrcuugm.d1l - Backdoor
  • Ybrcuugm.dll - Keylogger

Note: the file size of Ybrcuugm.d1l might vary due to garbage code appended at the end of the file.

It will also drop the following driver that will communicate with the dll files in order to hide the malware's processes, registry entries and files:

  • %sysdir%\drivers\Ybrcuugm.sys

Moreover it also hides some network traffic that the PcClient.VK uses.

It modifies the following known registry entry as its autostart technique:

Data before:

  • [HKLM\SYSTEM\CurrentControlSet\Services\dmserver\Parameters] ServiceDll = %sysdir%\dmserver.dll

Data after:

  • [HKLM\SYSTEM\CurrentControlSet\Services\dmserver\Parameters] ServiceDll = %sysdir%\Ybrcuugm.d1l

In order for the system to work normally, Ybrcuugm.dll will execute its malicious routine and then pass the correct parameter to the original dmserver.dll.

It also adds the following autostart registry entry for the driver:

  • [HKLM\System\ControlSet001\Services\Ybrcuugm] ImagePath= C:\WINDOWS\system32\drivers\Ybrcuugm.sys

Part of its payload is that is logs all the keystrokes made by the user and saves it to the following file:

  • %sysdir%\log.txt

It then sends this file to a remote hacker.

Another part of the payload is that it has a backdoor component. The backdoor routine is injected into svchost.exe, which is capable doing the following:

  • updating itself
  • remote execution

This malware connects to the following site:

  • https://baas.8866.org/[BLOCKED]ex.asp


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More