Backdoor.Hupigon
| Alert Level : | high |
| Discovered: | 2005Mar15 |
| Tag: | computer virus |
| Discoverer and Source: | http://www.bitdefender.com/ |
Malware Behavior and Technical Description
Internet traffic while no user program is accessing the network.
Presence of common Windows processes (iexplore.exe, calc.exe ...) that have no window.
Presence of a Windows service that have description string containing Chinese characters.
Written in Delphi, often packed with various packers: Hmimys, NsPack, Svkp, UPX, AsPack and others.
When first executed Hupigon copies itself to other location (usually windows folder) and deletes itself after that.
To ensure that it will start every time Windows starts it installs its copy as a Windows service with automatic startup type.
To hide its presence from a process list viewer (taskmgr.exe, tasklist.exe ...) it starts a common Windows program (iexplore.exe, svchost.exe, services.exe ...) and overwrites the program
Removal Backdoor.Hupigon instructions:
Please let BitDefender disinfect your files.
Need help? Live computer support via remote at SupportSpace |

