Home Malware Programs Trojans Mal/Behav-374

Mal/Behav-374

Posted: September 29, 2010

Mal/Behav-374 (aka Backdoor:Win32/Hupigon.EC) is a variant of a Trojan malware program designed to attack the Windows operating system. Backdoor:Win32/Hupigon.EC comes armed with spyware which steals private data from the targeted computer. Mal/Behav-374 will appear to be an executable file that shows characteristics of malware behaviour. Use a proven malware remover to terminate Backdoor:Win32/Hupigon.EC immediately once it has been detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\drivers\oreans32.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_OREANS32\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_OREANS32\0000][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_OREANS32][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oreans32\Enum][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oreans32\Security][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oreans32][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\oreans32\Enum][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\oreans32\Security][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\oreans32]
Loading...