Home Malware Programs Backdoors Backdoor:Win32/Hupigon.FN

Backdoor:Win32/Hupigon.FN

Posted: October 15, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 26
First Seen: October 15, 2012
OS(es) Affected: Windows

Backdoor:Win32/Hupigon.FN is a backdoor Trojan that runs as a service and opens a backdoor server on the affected computer. Once installed on the compromised PC, Backdoor:Win32/Hupigon.FN makes system changes by dropping potentially malicious files and registry entries. Backdoor:Win32/Hupigon.FN modifies the Windows Registry so that it can start automatically whenever you start your PC. Backdoor:Win32/Hupigon.FN allows attackers to gain remote access and control over the infected computer. Backdoor:Win32/Hupigon.FN connects to a remote server to receive commands from attackers that involve configuring Windows Terminal Services: enabling or disabling desktop sharing, modifying the listening port; controlling Windows services: creating, deleting, starting, and stopping services, and modifying service settings, performing port scans, and many other.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemRoot%\system32\sdna.flasher.dll File name: %SystemRoot%\system32\sdna.flasher.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Parameters = "ServiceDll" = "%SystemRoot%\system32\sdna.flasher.dll"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Parameters = "ImagePath" = "%SystemRoot%\System32\svchost.exe -k netsvcs"
Loading...