Content

W32/Hupigon.worm!64afc36a4982

Type
Program
SubType
Worm
Discovery Date
11/19/2009
Minimum DAT
5807 (11/19/2009)
Updated DAT
5807 (11/19/2009)
Minimum Engine
5400.1158
Description Added
11/19/2009
Description Modified
11/19/2009 1:24 PM (PT)

Tab Navigation

Characteristics

This software is not a virus or a Trojan. It is detected as a "potentially unwanted program" (PUP). PUPs are any piece of software that a reasonably security- or privacy-minded computer user may want to be informed of and, in some cases, remove. PUPs are often made by a legitimate corporate entity for some beneficial purpose, but they alter the security state of the computer on which they are installed, or the privacy posture of the user of the system, such that most users will want to be aware of them.

File PropertyProperty Value
FileNamesvchot.exe
McAfee ArtemisArtemis!64afc36a4982
McAfee DetectionGeneric PUP.x
Length308,224 bytes
CRCC0717E22
MD564AFC36A4982C4102CA0293FADF5FC93
SHA13656F781242A6AEA245F1BAFFA347CF77A2A3A00

Other Common Detection Aliases

Company NameDetection Name
ahnlabWin-Trojan/Inject.702464
avastWin32:KillAV-KD [Trj]
AVG (GriSoft)backdoor.hupigon4.zms
AviraBDS/Backdoor.Gen
BitDefenderTrojan.Inject.GO
clamavTrojan.Agent-54752
Dr.WebBackDoor.Beizhu.2315
EMSI SoftwareBackdoor.Win32.Hupigon!ik
eSafe (Alladin)suspicious Trojan/Worm [101]
Eset~a variant of Win32/Hupigon
FortiNetMisc/PUP
F-ProtW32/Downloader.C.gen!Eldorado
KasperskyBackdoor.Win32.Hupigon.dvti
microsoftWorm:Win32/Autorun.PP
normanw32/hupigon.gen16
pandaBck/Hupigon.AZG
risingBackdoor.Win32.ShangXing.kd
SophosMal/Behav-058
SymantecSuspicious.MH690
Trend MicroBKDR_HPGN.AA
vba32MalwareScope.Trojan-PSW.Game.16
V-BusterBackdoor.Hupigon.evtf
Vet (Computer Associates)
Win32/Dowque!generic

Avert® Labs has observed the following system activities:

ActivityRisk Level
Modifies memory of other processes
Critical
Writes executable in the windows folder
Low
Performs a shell execute of downloaded or existing files
Informational

Other detections that have been observed.

FileNameMcAfee Supported
%PROGRAMFILES%\_svchot.exe
Generic PUP.x

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following files were analyzed:

  • %USERPROFILE%\local settings\temp\svchot.exe
  • The following files have been added to the system:

  • %PROGRAMFILES%\_svchot.exe
  • %WINDIR%\system32\svchot.exe
  • Removal

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Aliases

    Aliases

      N/A