Backdoor

How to remove “Backdoor:Win32/Hupigon!B”?

Malware Removal

The Backdoor:Win32/Hupigon!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Hupigon!B virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Hupigon!B?


File Info:

name: DE65D006C1876D2DBA1F.mlw
path: /opt/CAPEv2/storage/binaries/b384d26c3e7a0a8705de652b247ae52cd7136190a89d3367e0e0c80051b3a85d
crc32: B6C4623B
md5: de65d006c1876d2dba1fef73c49be360
sha1: a724ae9028c617ab7101a247bca35843a4b1f69f
sha256: b384d26c3e7a0a8705de652b247ae52cd7136190a89d3367e0e0c80051b3a85d
sha512: 0a9afff3e90037e9bb9f63406f56f27dd95b66f4920ba47e84a678d6b8b46fd04887e16c48ab380ea8a0954c05158950d6369d3805124e1850608d436741fec7
ssdeep: 24576:FksVocaW5A5b3m+s2svwsIZLVWirg1wwE:FdAHxJkisk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CF47C22F6919477D1732B389C1B63599839BF102E28A84B3BF41E5C9F797823D252D3
sha3_384: 065b1caabe23b69f5cf215a46ef93e17c4b4f88d04ceda953af00d4386b6f80f1ec3c715761959dcbe90b74a4de16f35
ep_bytes: 558becb9040000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Beijing Rising Information Technology Co., Ltd.
FileDescription: Rising RsShell
FileVersion: 21, 0, 0, 5
InternalName: Beijing Rising Information Technology Co., Ltd.
LegalCopyright: Copyright(C) 2008 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.
OriginalFilename: Rsmain.exe
ProductName: Rising Antivirus 2009
ProductVersion: 21.00
SpecialBuild: 20080827133313421
Translation: 0x0804 0x03a8

Backdoor:Win32/Hupigon!B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.l2g7
AVGWin32:Hupigon-AHB [Trj]
MicroWorld-eScanGen:Malware.Heur.2.!copidmbe!.WK0@bm9OmDhb
FireEyeGeneric.mg.de65d006c1876d2d
SkyhighBehavesLike.Win32.PWSGoft.bh
McAfeeGenericRXHO-RL!DE65D006C187
Cylanceunsafe
ZillyaTrojan.Hupigon.Win32.8912
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Hupigon.012caa94
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.6c1876
VirITBackdoor.Win32.Hupigon.JOHG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Hupigon
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Graybird-28
KasperskyBackdoor.Win32.Hupigon.mxzs
BitDefenderGen:Malware.Heur.2.!copidmbe!.WK0@bm9OmDhb
NANO-AntivirusTrojan.Win32.Hupigon.dxkzlg
AvastWin32:Hupigon-AHB [Trj]
TencentMalware.Win32.Gencirc.10b2bbae
SophosMal/Hupig-H
F-SecureBackdoor:W32/Hupigon.OJY
DrWebTrojan.PWS.Vipgsm.788
VIPREGen:Malware.Heur.2.!copidmbe!.WK0@bm9OmDhb
TrendMicroBKDR_HUPIGON.GEN
Trapminemalicious.high.ml.score
EmsisoftGen:Malware.Heur.2.!copidmbe!.WK0@bm9OmDhb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Huigezi.2007.bgwz
VaristW32/Hupigon.J.gen!Eldorado
AviraBDS/Hupigon.Gen
Antiy-AVLTrojan/Win32.Hupigon.pv
KingsoftWin32.HeurC.KVM008.a
MicrosoftBackdoor:Win32/Hupigon.gen!B
XcitiumBackdoor.Win32.Hupigon.UUE0@1o8eqw
ArcabitGen:Malware.Heur.2.!copidmbe!.E84E62
ZoneAlarmBackdoor.Win32.Hupigon.mxzs
GDataWin32.Trojan.PSE.14IIXYG
GoogleDetected
AhnLab-V3Win-Trojan/Hupigon.Gen
BitDefenderThetaAI:Packer.E687A2D426
MAXmalware (ai score=100)
VBA32OScope.Backdoor.Hupigon.axbr
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallBKDR_HUPIGON.GEN
RisingBackdoor.Win32.Gpigeon2009.aaj (CLASSIC)
YandexTrojan.GenAsa!uWXImPdZ5lY
IkarusBackdoor.Win32.Hupigon
MaxSecureTrojan.Malware.1634706.susgen
FortinetW32/Hupigon.OSE!tr.bdr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudBackdoor:Win/Graftor

How to remove Backdoor:Win32/Hupigon!B?

Backdoor:Win32/Hupigon!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment