ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE – Backdoor Hupigon removal

FileMD5Virus Alias
ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE 481902cf737141d7e0587bfd3325bd97 Backdoor Hupigon

ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE size: 881875 bytes

Created files:

%Program Files%\Gxahu\Khokx.exe
%Program Files%\Gxahu\Olhb.exe
%Program Files%\Gxahu\Zkaq\Fsoe.dll
%TEMP%\g8E\OneKeySoft.FlashMemoryMagic.v1.3.15.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Gxahu\Olhb.exe

Detected by UnHackMe:

ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE
Default location: %TEMP%\G8E\ONEKEYSOFT.FLASHMEMORYMAGIC.V1.3.15.EXE

Leave a Reply