Backdoor.Win32.Hupigon.bns

tag:Backdoors  

The backdoor can:

  • provide full access to files on the user
    1. Use Task Manager to terminate the backdoor process
    2. Delete the original backdoor file (the location will depend on how the program originally penetrated the victim machine).
    3. Delete the following file: %WinDir%\G_Server2006Key.DLL
    4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

    This backdoor will give a remote malicious user full access to the victim machine. The program is a Windows DLL file. The file size may vary significantly.

    Installation

    This backdoor will be installed on the victim machine by another malicious program.

    When installing, the backdoor extracts a DLL file from its executable file and saves it to the Windows root directory under the following name:

    %WinDir%\G_Server2006Key.DLL

    This file will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Hupigon.bxb.

    Payload

©Virus-Encyclopedia.com All Rights Reserved.