SUPEREC.IO.SYS – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SUPEREC.IO.SYS – Backdoor Hupigon removal

File MD5 Virus Alias
SUPEREC.IO.SYS b5307cb65ddd5cb468e94b11c9db01ed Backdoor Hupigon
SUPEREC.IO.SYS b5307cb65ddd5cb468e94b11c9db01ed Trojan SuspiciousFile
SUPEREC.IO.SYS b5307cb65ddd5cb468e94b11c9db01ed Trojan Generic

SUPEREC.IO.SYS size: 3840 bytes
SUPEREC.IO.SYS hash: B5307CB65DDD5CB468E94B11C9DB01ED

Created files:

C:\Documents and Settings\QQCRT.DLL
%Program Files%\Garss.exe
C:\Server.exe
%SysDir%\superec.io.sys
C:\??????.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\Start: 02000000
HKLM\System\CurrentControlSet\Services\BITS\Parameters\ServiceDll: 43003A005C0044006F00630075006D0065006E0074007300200061006E0064002000530065007400740069006E00670073005C00510051004300520054002E0044004C004C000000
HKLM\System\CurrentControlSet\Services\TianSinl\Type: 01000000
HKLM\System\CurrentControlSet\Services\TianSinl\Start: 03000000
HKLM\System\CurrentControlSet\Services\TianSinl\DisplayName: TianSinl
HKLM\System\CurrentControlSet\Services\TianSinl\ImagePath: %WinDir%\System32\superec.io.sys

Detected by UnHackMe:

SUPEREC.IO.SYS
Default location: %SYSDIR%\SUPEREC.IO.SYS

Dropper information:
MD5: 9bb0f2141782485ee8cac6da05128feb
File size: 374028 bytes

Leave a Reply