FinalFantasy 1.04
(Backdoor.Win32.Hupigon.ghqc)
(Backdoor.Win32.Hupigon.btrm for Server)

by Amoeba

Released in May 2008

Made in China

more versions


Server
Dropped File:
c:\WINDOWS\F_Server.exe
Size: 716,288 bytes    

Added to Registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FinalFantasy_Service "ImagePath"
Data: C:\WINDOWS\F_Server.exe 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FinalFantasy_Service "ImagePath"
Data: C:\WINDOWS\F_Server.exe 






Tested on Windows XP
May 20, 2008

MegaSecurity