Backdoor

Backdoor.Hupigon removal guide

Malware Removal

The Backdoor.Hupigon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Hupigon virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Installs an hook procedure to monitor for mouse events
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Detected Armadillo packer using a known mutex
  • Detected Armadillo packer using a known registry key
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.sina.com.cn
pig.zhongsou.com

How to determine Backdoor.Hupigon?


File Info:

crc32: 8ADE33AA
md5: 0449534c5e54a7471a1dfe33964e6e7f
name: contrav.1.9.exe
sha1: 6f063a545af3b3932caf4d8e3a466865061df4da
sha256: 16a8715edac9b1c05deefecb8ea5768db1f0b203da463040c2d27013f414e5a2
sha512: 6fe0989309f23746ea089a98c23c638eee6f4e9a8aa728d0b580258fb24ac448ad664e21ff48693a37a1b79c6870004cb6e5875e52e11019f36471c7bd466bc1
ssdeep: 98304:r+rMoqMxKDlJHgE4ZCZu4MIi+rkbn04Pi01bs:rqKIgJHgnkoSi+UFPiis
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Hupigon also known as:

MicroWorld-eScanGen:Trojan.Heur.y3Z@vTJVDOfbn
FireEyeGen:Trojan.Heur.y3Z@vTJVDOfbn
Qihoo-360HEUR/Malware.QVM18.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005092581 )
BitDefenderGen:Trojan.Heur.y3Z@vTJVDOfbn
K7GWTrojan ( 005092581 )
Cybereasonmalicious.c5e54a
BitDefenderThetaAI:Packer.597B65001D
F-ProtW32/Backdoor.AIDM
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Hupigon.EHC
AvastWin32:Cnnic-C [PUP]
GDataGen:Trojan.Heur.y3Z@vTJVDOfbn
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Hupigon.81ce36c7
NANO-AntivirusTrojan.Win32.Hupigon.bcfqmy
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareGen:Trojan.Heur.y3Z@vTJVDOfbn
SophosMal/Generic-S
ComodoBackdoor.Win32.Hupigon.EHC@39n6
F-SecureDropper.DR/Delphi.Gen
ZillyaTrojan.Hupigon.Win32.8938
McAfee-GW-EditionArtemis!Trojan
SentinelOneDFI – Suspicious PE
Trapminesuspicious.low.ml.score
EmsisoftGen:Trojan.Heur.y3Z@vTJVDOfbn (B)
APEXMalicious
CyrenW32/Backdoor.XSAZ-0226
JiangminBackdoor/Huigezi.hlv
WebrootW32.Trojan.Gen
AviraDR/Delphi.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Heur.EDDE71
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Occamy.C
McAfeeArtemis!0449534C5E54
MAXmalware (ai score=100)
VBA32Backdoor.Hupigon
TencentWin32.Trojan.Delphi.Dbd
YandexTrojan.Hupigon!DS87QPCG7f0
IkarusBackdoor.Win32.Hupigon
FortinetW32/Hupigon.EHC
AVGWin32:Cnnic-C [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Backdoor.Hupigon?

Backdoor.Hupigon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment