ZRundlll.exe – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ZRundlll.exe – Backdoor Hupigon removal

FileVirus Alias
ZRundlll.exe Backdoor Hupigon
ZRundlll.exe Trojan Delf
ZRundlll.exe Trojan Small
ZRundlll.exe Trojan Agent
ZRundlll.exe Trojan Generic

Created files:

%SysDir%\ZRundlll.exe – Backdoor Hupigon

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ZRundlll\Type: 10010000
HKLM\System\CurrentControlSet\Services\ZRundlll\Start: 02000000
HKLM\System\CurrentControlSet\Services\ZRundlll\DisplayName: Windows Rwxz
HKLM\System\CurrentControlSet\Services\ZRundlll\ImagePath: %WinDir%\System32\ZRundlll.exe -NetSata

Detected by UnHackMe:

ZRundlll.exe
Default location: %SysDir%\ZRundlll.exe

Dropper information:
SHA256: a5f0fcce153130947384ddff96bd42cac72af218e057f4baea01921e9d22e010
SHA1: 359f3d5021e0e5e967687bbec533e25b64bba44b
MD5: 94f7598c468142595ff468c5f42ab0c8
File size: 796806 bytes

Leave a Reply