GEUXX.DLL – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

GEUXX.DLL – Backdoor Hupigon removal

FileMD5Virus Alias
GEUXX.DLL 23d059e000ff400e538ef05fd9a726ec Backdoor Hupigon
GEUXX.DLL 23d059e000ff400e538ef05fd9a726ec Trojan Eldorado
GEUXX.DLL 23d059e000ff400e538ef05fd9a726ec Backdoor Pigeon
GEUXX.DLL 23d059e000ff400e538ef05fd9a726ec Trojan Agent
GEUXX.DLL 23d059e000ff400e538ef05fd9a726ec Trojan Delf

GEUXX.DLL size: 872752 bytes
GEUXX.DLL hash: 23D059E000FF400E538EF05FD9A726EC

Created files:

%Program Files%\Aygr\Ehko\Geuxx.dll
%Program Files%\Aygr\Vowu.exe
%Program Files%\Aygr\Xlabq.exe
%TEMP%\g810\SSW.Time.PRO.NET.v9.18-BEAN.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Aygr\Xlabq.exe

Detected by UnHackMe:

GEUXX.DLL
Default location: %PROGRAM FILES%\AYGR\EHKO\GEUXX.DLL

Dropper information:
MD5: 6f76d815ba5c8d14e1c32b81b70fb03c
File size: 10163718 bytes

Leave a Reply