Backdoor Hupigon – G_Server2.0.exe – 0b6952b4611b93875cdfac755497b927

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Hupigon
Also known as: Trojan Crypt, Trojan OnLineGames
SHA256: 5691f65a53acbc2dcae566ed407d9f94babf85f230089f8178284a7dfae8ae1b
SHA1: 7abd46f53fd33cc5d8eb29d7db699f6341c13f1f
MD5: 0b6952b4611b93875cdfac755497b927
File size: 326656 bytes

Created files:

%WinDir%\G_Server2.0.exe – Backdoor Hupigon
%SysDir%\god.sys – Backdoor Hupigon
%SysDir%\ranx.dll – Backdoor Hupigon

Backdoor Hupigon created autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distributed Link Tracking\Type: 10010000
HKLM\System\CurrentControlSet\Services\Distributed Link Tracking\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distributed Link Tracking\DisplayName: Distributed Link Tracking
HKLM\System\CurrentControlSet\Services\Distributed Link Tracking\ImagePath: %WinDir%\G_Server2.0.exe
HKLM\System\CurrentControlSet\Services\VANTI\Type: 01000000
HKLM\System\CurrentControlSet\Services\VANTI\Start: 02000000
HKLM\System\CurrentControlSet\Services\VANTI\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\VANTI\DisplayName: VANTI
HKLM\System\CurrentControlSet\Services\VANTI\ImagePath: %WinDir%\System32\god.sys

Leave a Reply