QQNEWS.EXE – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

QQNEWS.EXE – Backdoor Hupigon removal

File MD5 Virus Alias
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Backdoor Hupigon
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Trojan PAK_Generic
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Trojan WS.Reputation
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Trojan SuspiciousFile
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Trojan Generic
QQNEWS.EXE ed721a3a3b437a4c99375da63280d8cb Trojan Downloader

QQNEWS.EXE size: 60928 bytes
QQNEWS.EXE hash: ED721A3A3B437A4C99375DA63280D8CB

Created files:

%Program Files%\QQNews\QQNews.exe
%WinDir%\conime\iexplorer.exe
%WinDir%\conime\SSDT01.sys
%WinDir%\Cursors\taskhost.exe
%WinDir%\iklahbgj.exe
%WinDir%\kahiekjd.exe
%WinDir%\nabloskf.exe
%WinDir%\NBBBBBB.exe
%WinDir%\nlvabhdfj.exe
%WinDir%\pkablfn.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\S\Type: 01000000
HKLM\System\CurrentControlSet\Services\S\Start: 03000000
HKLM\System\CurrentControlSet\Services\S\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\S\DisplayName: S
HKLM\System\CurrentControlSet\Services\S\ImagePath: %WinDir%\conime\SSDT01.sys
HKLM\System\CurrentControlSet\Services\Schedulo\Type: 10010000
HKLM\System\CurrentControlSet\Services\Schedulo\Start: 02000000
HKLM\System\CurrentControlSet\Services\Schedulo\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Schedulo\DisplayName: Schedulo
HKLM\System\CurrentControlSet\Services\Schedulo\ImagePath: C:\Windows\Cursors\taskhost.exe Star
HKLM\System\CurrentControlSet\Services\Schedulo\ObjectName: LocalSystem
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\QQNews: “%Program Files%\QQNews\QQNews.exe” /r -Software\Microsoft\Wind

Detected by UnHackMe:

QQNEWS.EXE
Default location: %PROGRAM FILES%\QQNEWS\QQNEWS.EXE

Dropper information:
MD5: 0bc5efed3004d1d5e1fc01aeee32a0d1
File size: 1862493 bytes

Leave a Reply