BKDR_PLUGX.BUT

By Domesticus in Backdoors | 10 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

BKDR_PLUGX.BUT Description

BKDR_PLUGX.BUT is a backdoor Trojan that is distributed to the affected computer by other computer infections, specifically BKDR_PLUGX.SME. BKDR_PLUGX.BUT is a remote access tool (RAT) recognized as PlugX. BKDR_PLUGX.BUT is one of the most common malware threats used in conducting targeted attacks which are mainly directed towards Japanese government institutions. BKDR_PLUGX.BUT performs commands given by remote attackers in order to infect targeted computer systems. BKDR_PLUGX.BUT records keystrokes and active window of a victimized computer to steal confidential information.

BKDR_PLUGX.BUT connects to several domains and a C&C server to receive commands from cybercrooks for malicious activities. After installation, BKDR_PLUGX.BUT adds melevolent files. BKDR_PLUGX.BUT inserts itself into the svchost.exe process as component of its memory residency routine. BKDR_PLUGX.BUT registers its downloaded component as a system service by creating the certain registry entries and keys so that it can launch automatically whenever Windows is started.

Type: Backdoors

How Can You Detect BKDR_PLUGX.BUT?

BKDR_PLUGX.BUT Removal Details

BKDR_PLUGX.BUT has typically the following processes in memory:

  • All Users’ %User Profile%\Gf\NvSmartMax.dll

BKDR_PLUGX.BUT creates the following files in the system:

  • {All Users’ Profile}\Gf\kl.log
  • All Users’ %User Profile%\Gf\boot.ldr – detected as TROJ_PLUGX.SME
  • All Users’ %User Profile%\Gf\NvSmart.exe – a legitimate NVIDIA (NVIDIA Smart Maximise Helper Host)

BKDR_PLUGX.BUT creates the following registry entries:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf Description = “Gf”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FAST
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf\Security
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf\Enum;
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf ImagePath = “”All Users’ %User Profile%\Gf\NvSmart.exe” 200 0″
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf Type = “110″
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf Start = “2″
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf ErrorControl = “0″
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf DisplayName = “Gf”
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gf ObjectName = “LocalSystem”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FAST CLSID = “{random hex values}”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 09/21/12 and posted on 09/21/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.