Home Malware Programs Backdoors Backdoor.Win32.Hupigon.ilgj

Backdoor.Win32.Hupigon.ilgj

Posted: January 22, 2010

Backdoor.Win32.Hupigon.ilgj is a malicious backdoor Trojan. Backdoor.Win32.Hupigon.ilgj runs in the background and enables attackers remote access and control of an infected system. Backdoor.Win32.Hupigon.ilgj will give attackers access to sensitive information that can be used for Identity theft. Backdoor.Win32.Hupigon.ilgj should be removed upon detection.

Aliases

VirTool:Win32/DelfInject.gen!X (Microsoft)
Win-Trojan/Hupigon.737280.AW (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\sddc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...