Backdoor

Backdoor:Win32/Hupigon.ZAK removal instruction

Malware Removal

The Backdoor:Win32/Hupigon.ZAK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Hupigon.ZAK virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Hupigon.ZAK?


File Info:

name: DB038C8948861FBDDA98.mlw
path: /opt/CAPEv2/storage/binaries/df6c7a8e6a649eec931b86ffcf17a85cceef8e9da14b479dcb7bf7e633fdfc05
crc32: 4016F7C4
md5: db038c8948861fbdda98f3a33b30b648
sha1: 09dc42b251d1d1e6676b6a37ec700ca5bf08a9bb
sha256: df6c7a8e6a649eec931b86ffcf17a85cceef8e9da14b479dcb7bf7e633fdfc05
sha512: 6099a5a0d0a56b166cc1f2220a83b3e0cb6b081a299f5736faf8d2c70ef7676399f3fae69cd06723e136968be5536227ec5aa5fce466d3f8b6bcb4a558acc718
ssdeep: 3072:Y5UF1x65fjLUIPCyntB867u/ECRvmg5hwawUAlY6Aw3SSkjV0uS:Y5m1xYDCyX86q/xM2wTXK6Aw3SSfr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194148E12F5C681FBDA9201381DF97B7A973BFD744B199A837350CA5C1CB20929B1A387
sha3_384: eaaeb4f160ce164638f160cb33d0209462e3b393de0d09f6c5b91a40c3f9fe3e34ece3109504d6eed2955da39f5192d5
ep_bytes: 558bec6aff68004f410068f070400064
timestamp: 2010-02-01 09:20:35

Version Info:

Comments:
CompanyName: 360Safe.com
FileDescription: 360安全卫士免疫模块
FileVersion: 2, 0, 0, 3000
InternalName: antiplg
LegalCopyright: Copyright (C) 2006 360Safe.com
LegalTrademarks:
OriginalFilename: antiplg.dll
PrivateBuild:
ProductName: 360安全卫士免疫模块
ProductVersion: 2, 0, 0, 3000
SpecialBuild:
Translation: 0x0804 0x04b0

Backdoor:Win32/Hupigon.ZAK also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.db038c8948861fbd
McAfeeBackDoor-DVB.r.e
CylanceUnsafe
VIPRETrojan.Win32.Redosdru.C (v)
SangforTrojan.Win32.Generic.ky
AlibabaBackdoor:Win32/Hupigon.7cbca65e
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Backdoor.XWZZ-6250
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Fusing.AM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Magania.3.CF827ABA
NANO-AntivirusTrojan.Win32.Farfli.dgjyyz
MicroWorld-eScanGeneric.Magania.3.CF827ABA
AvastWin32:Farfli-BD [Trj]
TencentWin32.Trojan.Obfuscator.Wqml
Ad-AwareGeneric.Magania.3.CF827ABA
ComodoTrojWare.Win32.TrojanDropper.Agent.xkd1@1mkr97
DrWebTrojan.PWS.Gamania.46158
ZillyaTrojan.Magania.Win32.30525
TrendMicroTROJ_REDOS.SM2
EmsisoftGeneric.Magania.3.CF827ABA (B)
IkarusBackdoor.Win32.Inject
GDataGeneric.Magania.3.CF827ABA
JiangminTrojan/KillAV.cck
WebrootTrojan:Win32/Redosdru.K
AviraTR/Drop.Agent.xkd
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2206E47
MicrosoftBackdoor:Win32/Hupigon.ZAK
AhnLab-V3Trojan/Win32.Magania.C77497
BitDefenderThetaGen:NN.ZexaF.34212.lm1@aOz18@ab
ALYacGeneric.Magania.3.CF827ABA
VBA32BScope.Trojan.Skeeyah
TrendMicro-HouseCallTROJ_REDOS.SM2
RisingTrojan.Killav!1.6545 (CLOUD)
YandexTrojan.GenAsa!mxfadPe+csc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Redosdru.BED!tr
AVGWin32:Farfli-BD [Trj]
PandaTrj/Genetic.gen

How to remove Backdoor:Win32/Hupigon.ZAK?

Backdoor:Win32/Hupigon.ZAK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment