ESET.NOD32.3.0.667.70.YEARS.HA.EXE – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ESET.NOD32.3.0.667.70.YEARS.HA.EXE – Backdoor Hupigon removal

FileMD5Virus Alias
ESET.NOD32.3.0.667.70.YEARS.HA.EXE dd43f85f3115faa107e504ace7d0729d Backdoor Hupigon

ESET.NOD32.3.0.667.70.YEARS.HA.EXE size: 20422723 bytes
ESET.NOD32.3.0.667.70.YEARS.HA.EXE hash: DD43F85F3115FAA107E504ACE7D0729D

Created files:

%Program Files%\Jgodv\Aizku\Caoye.dll
%Program Files%\Jgodv\Czur.exe
%Program Files%\Jgodv\Ukiou.exe
%TEMP%\g833\Eset.NOD32.3.0.667.70.Years.HA.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Jgodv\Czur.exe

Detected by UnHackMe:

ESET.NOD32.3.0.667.70.YEARS.HA.EXE
Default location: %TEMP%\G833\ESET.NOD32.3.0.667.70.YEARS.HA.EXE

Dropper information:
MD5: cd574f9b0fb8f517bfd9c4e56b83be9c
File size: 22367535 bytes

Leave a Reply