Backdoor.WIN32.hupigon.dccn infection

Status
Not open for further replies.
Joined
May 27, 2002
Messages
10,989
Location
Canberra ACT Australia
a-squared Free can find 51 infections but zero booted in SAFE mode. After scan if I select quarantine it does not and if I select delete it instantly restarts and all 51 are still there after new scan. Neither SAS or Spyware Doctor can help. Do I need to turn off System Restore before scan and delete to kill it? Any ideas appreciated
 
1. Turn off System Restore
2. Download Avast! and install. When it asks if you want to run a boot-time scan, hit YES.

See if this clears it up.

I would also suggest running a full system scan after you run the boot scan.

Please report back as to how this worked out for you.

-Chris
 
Should I shut down Panda Platinum Internet Security, Spywareblaster etc after downloading AVAST and then scan as I've heard multiple AV's are not a good idea? thanks..s
 
Be careful with installing several anti-virus programs. I did this once and the computer had major problems with booting up.

From what I understand, always use one anti-virus program. If you will install Avast, disable your other anti-virus program.
 
Sprintman if you are using the latest version of Panda the rescue CD runs a version of Linux so that you have an alternative O/S. You can run Panda from the CD using this alternative O/S to check your computer. That alternative O/S cannot be affected easily by Windows viruses, worms, or Trojan Horse programs.

Bitdefender also uses a version of Linux on its rescue CD. And from that rescue CD you can do rootkit checks.
 
Was it Panda that identified it as the above?

Research on this infection lists it as Malware, NOT a virus or Trojan, which is likely why Avast! didn't find it.

Do you have Spybot?
 
sprintman, did you start up from the Panda installation CD? Put the CD in the computer and restart the computer. Unless the computer has been setup so that it can't start from the CD you should be given a choice whether to start up from the CD or not. The CD runs a version of Linux which is a compact O/S, can't be affected by Windows viruses very easily, and is on a writ-protected CD in any case. Running from the Linux Panda CD it may be able to remove the malware. Worth a shot. Is there any harm in trying it?
 
Also, save your documents and stuff to an external hard drive. You may have to in the end format the hard drive. And then reinstall your O/S and your applications. Before reinstalling your documents they will need to be scanned with antivirus software.
 
I noticed that you said Panda 2006. I don't know if the 2006 version of Panda had a rescue CD running Linux or not. The latest version of Panda does run Linux on the rescue CD.

If you are willing to try a different antivirus Bitdefender also has the installation disc as the rescue disc running a version of Linux.

Even if you can remove the malware it is probably better in the long run to save your stuff to an external hard drive and format the hard drive. And then reinstall the O/S and applications. And before reinstalling the documents scan everything with antivirus software.
 
Originally Posted By: Drew99GT
It's a trojan backdoor/downloader.

http://www.viruslist.com/en/viruses/encyclopedia?virusid=44430

I'd try scanning with

http://support.f-secure.com/enu/home/ols.shtml#

http://www.eset.com/onlinescan/index.php

Might want to try asking in the SAS forum. Have you tried scanning with SAS in safe mode?

I doubt spybot will do a anything for you as this is a serious piece of malware.


Yup, you are right, it is listed a Trojan (though he has the dcc variant, not the "a" variant that you linked to, not much info on the dcc, it's newer)

http://www.viruslist.com/en/viruses/encyclopedia?virusid=142731

The original place I checked just listed it as basic malware.

Trend-Micro's Housecall might also be another good one to try.

You'd be surprised what Spybot can remove in Safe Mode. I know I have been.
 
Originally Posted By: Mystic

Even if you can remove the malware it is probably better in the long run to save your stuff to an external hard drive and format the hard drive. And then reinstall the O/S and applications. And before reinstalling the documents scan everything with antivirus software.


I agree 100000000000000%. The absolute best antimalware software is backup software. Infected? Why screw around for weeks on end trying to get rid of it. Reload a disk image and 20 minutes later you're back to good.

Plus, I'd never trust a malware infection removal 100%.
 
Originally Posted By: Drew99GT
Originally Posted By: Mystic

Even if you can remove the malware it is probably better in the long run to save your stuff to an external hard drive and format the hard drive. And then reinstall the O/S and applications. And before reinstalling the documents scan everything with antivirus software.


I agree 100000000000000%. The absolute best antimalware software is backup software. Infected? Why screw around for weeks on end trying to get rid of it. Reload a disk image and 20 minutes later you're back to good.

Plus, I'd never trust a malware infection removal 100%.



Oh yes, getting rid of them COMPLETELY takes HOURS upon HOURS of time (depending on the infection). Including frequent usage of regedit and even then, there can be traces.

A quick wipe and restore is substantially quicker if the data has been backed up.
 
Last edited by a moderator:
No CD as I purchased online. Panda updated daily, catches lots of stuff. Running F-Secure scan now. Will do SAS in safe mode later. Will run Kaspersky as well. a-squared think it a false positive but I'm taking no chances. I need to invest in backup disk and software ASAP. Many thanks for all replies...s
 
Status
Not open for further replies.
Back
Top Bottom