HCAX.DLL – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

HCAX.DLL – Backdoor Hupigon removal

File MD5 Virus Alias
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Backdoor Hupigon
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Trojan Generic
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Trojan Eldorado
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Backdoor Pigeon
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Trojan Agent
HCAX.DLL 378DCF58E0A0036C03493812CF464931 Trojan Delf

HCAX.DLL size: 872798 bytes
HCAX.DLL hash: 378DCF58E0A0036C03493812CF464931

Created files:

%Program Files%\Bkxur\Odge\Hcax.dll
%Program Files%\Bkxur\Ootf.exe
%Program Files%\Bkxur\Vaty.exe
%TEMP%\g812\StreamingStar.URL.Helper.v3.03.WinAll.Incl.Keygen-CRD.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Bkxur\Ootf.exe

Detected by UnHackMe:

HCAX.DLL
Default location: %PROGRAM FILES%\BKXUR\ODGE\HCAX.DLL

Dropper information:
MD5: 9FE8A85771AC1EF3BF0CE4BACB9CBA2B
File size: 3032210 bytes

Leave a Reply