Backdoor

Backdoor:Win32/Popwin!E removal instruction

Malware Removal

The Backdoor:Win32/Popwin!E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Popwin!E virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Popwin!E?


File Info:

name: 69FFED34DF5204F126B0.mlw
path: /opt/CAPEv2/storage/binaries/806c3b64e11aadf0f606f6eb772e33099d95c173927857ee249b3383c8358564
crc32: F795A3F8
md5: 69ffed34df5204f126b0d13f0fd349c4
sha1: 08b0dc20d5e0fa34f8cbd5cd8c6fba0b4852bce1
sha256: 806c3b64e11aadf0f606f6eb772e33099d95c173927857ee249b3383c8358564
sha512: b7960f8d6fe80d8c159e40f9a9277290d262a530c24af5481def11e5bb2b5650d2ab5d3debef6b0fe3af9e14a29a5f8728497d21fb3374e7bd273f949cdb743d
ssdeep: 384:0vT8WXAkli5TuBsfm46Cm6FvAG3nRlni6NqshAxPr6+e9Pfqbn1:YYml6KBsmVAASbyxeha5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B392C023EE6940FBD0C7B17350466AC17FA4A983492283EF792844AFB825C29F709652
sha3_384: c8d72684aa381b89f26d9c3698591a98c2cd6fa4f002aca88ab2e309ed328c3a6ecd02c914f8dbb89e2e12fd8be4621d
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2008-10-15 09:07:16

Version Info:

Translation: 0x0409 0x04e4

Backdoor:Win32/Popwin!E also known as:

LionicTrojan.Win32.Agent.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Malware.SB!dld!g.04D26B43
FireEyeGeneric.mg.69ffed34df5204f1
McAfeegeneric!bg
CylanceUnsafe
ZillyaTrojan.Agent.Win32.201261
SangforSpyware.Win32.Agent.V7kp
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderGeneric.Malware.SB!dld!g.04D26B43
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_70% (W)
BaiduWin32.Trojan-Downloader.Agent.jj
CyrenW32/Injector.A.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Flux
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-112756
KasperskyUDS:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Popwin.f3e1cbab
NANO-AntivirusTrojan.Win32.ARSleep.gcbz
ViRobotTrojan.Win32.Z.Spy.19968
RisingWorm.Win32.Agent.zm (CLOUD)
Ad-AwareGeneric.Malware.SB!dld!g.04D26B43
SophosMal/Generic-R + Mal/Behav-112
ComodoTrojWare.Win32.Magania.~L@f80vl
DrWebTrojan.Popuper.14211
VIPREGeneric.Malware.SB!dld!g.04D26B43
TrendMicroTROJ_GEN.R067C0CGM22
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lh
Trapminemalicious.high.ml.score
EmsisoftGeneric.Malware.SB!dld!g.04D26B43 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.mlk
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24D
MicrosoftBackdoor:Win32/Popwin.gen!E
GDataGeneric.Malware.SB!dld!g.04D26B43
GoogleDetected
AhnLab-V3Trojan/Win32.Downloader.C140618
BitDefenderThetaAI:FileInfector.440D6C6A12
ALYacGeneric.Malware.SB!dld!g.04D26B43
MAXmalware (ai score=88)
VBA32BScope.Trojan.Download
MalwarebytesMalware.Heuristic.1004
PandaW32/Winko.AF.worm
TrendMicro-HouseCallTROJ_GEN.R067C0CGM22
TencentWin32.Trojan.Spy.Eajl
YandexTrojan.GenAsa!Zppc9YOnRiY
IkarusBackdoor.Win32.Popwin
MaxSecureTrojan.Malware.796708.susgen
FortinetW32/Agent.NLB!tr.bdr
AVGFileRepMalware [Trj]
Cybereasonmalicious.4df520
AvastFileRepMalware [Trj]

How to remove Backdoor:Win32/Popwin!E?

Backdoor:Win32/Popwin!E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment