Backdoor

Backdoor.Pigeon removal guide

Malware Removal

The Backdoor.Pigeon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Pigeon virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Pigeon?


File Info:

crc32: B9001CDF
md5: b9694661d5972e7da6cd8d81ba46fa40
name: B9694661D5972E7DA6CD8D81BA46FA40.mlw
sha1: a961689547adf5f6ae229b782aeae8696932a48a
sha256: dd609bae69f68cbf944f9fb1b8b1585ab53a3b18405533369147ade9fe1d0583
sha512: adf652165bb73cd6adb4e29fcc3114970ba92215587c0808487ca8161dabb90d60315ff0058a62583d3a353c15027c13b3ff861fa47a6ea480ad2b38b8f241bd
ssdeep: 6144:4V7VaHSusmhoHhCDiNN7M7SCnqMreKSnEhlWBkK1ZVCax2TfRpoSU/:4VBayusm+HhUEML5reKSEh+dvVtx2TJe
type: MS-DOS executable

Version Info:

LegalCopyright: Microsoft Corporation. All rights reserved.
InternalName: CSRSS.Exe
FileVersion: 5.1.2600.2180
CompanyName: Microsoft Windows Operating System
LegalTrademarks:
Comments:
ProductName: Microsoft Windows Operating System
ProductVersion: 5.1.2600.2180
FileDescription: Client Server Runtime Process
OriginalFilename: CSRSS.Exe
Translation: 0x0809 0x04e4

Backdoor.Pigeon also known as:

K7AntiVirusTrojan ( 005376ae1 )
LionicWorm.Win32.Fujack.kYPi
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Agent.AIYL
CylanceUnsafe
ZillyaBackdoor.Hupigon.Win32.1291
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Hupigon.7b25ee31
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.1d5972
CyrenW32/Backdoor.BUYN-9121
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Hupigon
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Hupigon-19686
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Agent.AIYL
NANO-AntivirusTrojan.Win32.Hupigon.jggf
MicroWorld-eScanTrojan.Agent.AIYL
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.Agent.AIYL
SophosMal/Generic-S
ComodoTrojWare.Win32.MalPack.~ULB@1pzy6g
BitDefenderThetaAI:Packer.6B6A65A91C
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_Xin1
McAfee-GW-EditionGeneric.dx!B9694661D597
FireEyeGeneric.mg.b9694661d5972e7d
EmsisoftTrojan.Agent.AIYL (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Huigezi.aig
WebrootW32.Bifrose.Gen
AviraTR/Crypt.FKM.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.9A857E
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Hupigon.DZ
GDataTrojan.Agent.AIYL
TACHYONBackdoor/W32.Hupigon.292875
AhnLab-V3Backdoor/Win32.Hupigon.C80591
Acronissuspicious
McAfeeGeneric.dx!B9694661D597
MAXmalware (ai score=100)
VBA32Backdoor.Pigeon
PandaGeneric Malware
TrendMicro-HouseCallCryp_Xin1
RisingPacker.Win32.Agent.j (CLASSIC)
YandexBackdoor.Hupigon.FENB
IkarusTrojan.Buzus.iij
MaxSecureTrojan.Malware.1579483.susgen
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor.Pigeon?

Backdoor.Pigeon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment