Backdoor Hupigon – HotPatch.sys – feab1e930affb25594879ec062786bcc

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Hupigon
Also known as: Trojan Agent, Trojan Delf
SHA256: 052537607131c28dc79d3e87df224c4520641c06192457ef7e41279f9a5f34a5
SHA1: de594ab5ad0a5dbe37e8068b7ecab555e4c43fa7
MD5: feab1e930affb25594879ec062786bcc
File size: 340480 bytes

Created files:

C:\HotPatch.sys – Backdoor Hupigon
%WinDir%\npptools.dll – Backdoor Hupigon
%WinDir%\Packet.dll – Backdoor Hupigon
%WinDir%\WanPacket.dll – Backdoor Hupigon
%WinDir%\wpcap.dll – Backdoor Hupigon
%Temp%\sichost.exe – Backdoor Hupigon
%Temp%\sochost.exe – Backdoor Hupigon
%Temp%\sschost.exe – Backdoor Hupigon

Backdoor Hupigon created autostart registry keys:

HKLM\System\CurrentControlSet\Services\9a5f8540\imagepath: 5C003F003F005C0043003A005C0044004F00430055004D0045007E0031005C0055005300450052005C004C004F00430041004C0053007E0031005C00540065006D0070005C00370032002E0074006D0070000000
HKLM\System\CurrentControlSet\Services\9a5f8540\type: 01000000

Leave a Reply