Backdoor

About “Backdoor.Hupigon.214242” infection

Malware Removal

The Backdoor.Hupigon.214242 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Hupigon.214242 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

ywgzs.2288.org

How to determine Backdoor.Hupigon.214242?


File Info:

crc32: 969214A0
md5: 0d884a9c35e285d6f6cff5b8c7a20c9f
name: 0D884A9C35E285D6F6CFF5B8C7A20C9F.mlw
sha1: 2b32307a4152b4361ed38262dd4c670bb2c804e2
sha256: 64d687fc13f87977bf56b22e9e06f51cea5053b3bde28652775f84c288486ff1
sha512: d9ae79d22093a1658c551e18114f695875bf29ddb9972095a1572bf63d561eba71b9965989dbc9b2c1ca88ea99f0332cea38b057d0bd5035d4268c9d787e0f3f
ssdeep: 12288:ERyTSktU4g/n/t0EW5A0zyYvJwQ5oAlK+GE4vebIk6bQQ52LgRg08y5Hpn7zC:oStU4gf2EW5A2DJr/kS4vGIk6v3Hv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Hupigon.214242 also known as:

TotalDefenseWin32/Hupigon.A!generic
MicroWorld-eScanBackdoor.Hupigon.214242
nProtectBackdoor/W32.Hupigon.761344.HA
CAT-QuickHealBackdoor.Hupigon.DI10
McAfeeBackDoor-AWQ.b
MalwarebytesBackdoor.Hupigon
K7AntiVirusBackdoor
TheHackerTrojan/Hupigon
NANO-AntivirusTrojan.Win32.Hupigon.ekqe
F-ProtW32/BackdoorX.UCQ
SymantecBackdoor.Graybird
NormanHupigon.gen146
TrendMicro-HouseCallBKDR_HUPIGON.EWE
AvastWin32:Hupigon-EA [Trj]
eSafeWin32.BackdoorHupigo
ClamAVTrojan.Delf-1066
KasperskyBackdoor.Win32.Hupigon.pv
BitDefenderBackdoor.Hupigon.214242
AgnitumBackdoor.Hupigon.GTB
ViRobotBackdoor.Win32.Hupigon.870912.F
SophosTroj/GrayBrd-CD
ComodoBackdoor.Win32.Hupigon
F-SecureBackdoor:W32/Hupigon.NMV
DrWebBackDoor.Pigeon.32525
VIPRETrojan.Win32.Generic!SB.0
AntiVirBDS/Hupigon.A
TrendMicroBKDR_HUPIGON.EWE
McAfee-GW-EditionHeuristic.BehavesLike.Win32.Suspicious-BAY.K
EmsisoftBackdoor.Hupigon.214242 (B)
JiangminBackdoor/Huigezi.qy
Antiy-AVLBackdoor/Win32.Hupigon.gen
KingsoftWin32.Hack.pcclient.u
MicrosoftBackdoor:Win32/Hupigon
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
GDataBackdoor.Hupigon.214242
CommtouchW32/BackdoorX.UCQ
AhnLab-V3Win-Trojan/Hupigon.761344.B
VBA32SScope.Backdoor.Win32.Hupigon.cmpw
PCTools255
ESET-NOD32Win32/Hupigon
RisingBackdoor.Gpigeon.fad
IkarusBackdoor.Win32.Hupigon
FortinetW32/Hupigon.FHA!tr.bdr
AVGBackDoor.Hupigon5.AWPZ
PandaBck/Hupigon.LHH

How to remove Backdoor.Hupigon.214242?

Backdoor.Hupigon.214242 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment