SERVER~1.EXE – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SERVER~1.EXE – Backdoor Hupigon removal

FileMD5Virus Alias
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Backdoor Hupigon
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Trojan SuspiciousFile
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Trojan Generic
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Backdoor Pigeon
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Backdoor PcClien
SERVER~1.EXE 639685248b3e192a67d1c841a3f348c8 Trojan Agent

SERVER~1.EXE size: 761344 bytes
SERVER~1.EXE hash: 639685248B3E192A67D1C841A3F348C8

Created files:

%WinDir%\system.exe
%TEMP%\IXP000.TMP\SERVER~1.EXE

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\Type: 10010000
HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\Start: 02000000
HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\DisplayName: GrayPigeon_Hacker.com.cn
HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\ImagePath: %WinDir%\System.exe

Detected by UnHackMe:

SERVER~1.EXE
Default location: %TEMP%\IXP000.TMP\SERVER~1.EXE

Dropper information:
MD5: 251201741d3f4aa588568ab643426873
File size: 648192 bytes

Leave a Reply