SYSTEM64.EXE – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSTEM64.EXE – Backdoor Hupigon removal

File MD5 Virus Alias
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Backdoor Hupigon
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Trojan Generic
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Trojan Eldorado
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Backdoor RBot
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Trojan CI
SYSTEM64.EXE 1fc8848bdc2b66f52d8aead511a8a115 Trojan Magania

SYSTEM64.EXE size: 43520 bytes
SYSTEM64.EXE hash: 1FC8848BDC2B66F52D8AEAD511A8A115

Created files:

%SysDir%\System64.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DRATSer\Type: 10010000
HKLM\System\CurrentControlSet\Services\DRATSer\Start: 02000000
HKLM\System\CurrentControlSet\Services\DRATSer\DisplayName: DRATRat
HKLM\System\CurrentControlSet\Services\DRATSer\ImagePath: %WinDir%\System32\System64.exe

Detected by UnHackMe:

SYSTEM64.EXE
Default location: %SYSDIR%\SYSTEM64.EXE

Dropper information:
MD5: 1fc8848bdc2b66f52d8aead511a8a115
File size: 43520 bytes

Leave a Reply