Trojan

Trojan:Win32/Audhi.B information

Malware Removal

The Trojan:Win32/Audhi.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Audhi.B virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Audhi.B?


File Info:

name: F245605AB44828F5356A.mlw
path: /opt/CAPEv2/storage/binaries/1e99e264231ba63bbec7c9accb5d82a2bc2b4e1b4c4f5b8a06bbe9eab531f650
crc32: 96292538
md5: f245605ab44828f5356a6d8cd41fe19e
sha1: b7b5517e5ed55aa3a728690682d7258d26e1cdd3
sha256: 1e99e264231ba63bbec7c9accb5d82a2bc2b4e1b4c4f5b8a06bbe9eab531f650
sha512: 0d241e0cad8e26d9cc61fe1452778e17332b304a7d8f62baab161b37062b1a3c84288356f1dfc859470e4753cbee88c8f752d4906564769570bd58d49011d5ad
ssdeep: 24:etGSbAHURZ/TraDtAQ91TqvRqDKhkiXbwFnfsAfjuI5BkNlYr2psoK35d:6k0qq07zdfsAfKUG0SuoK35d
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1BC71513617846EFCD2A80F32311F38AA107281B023A53086EF7826437FD46E749B9F52
sha3_384: 4cb4d3ed67b9153e2825650f2cb5929d29a86de79a067775e66ef3a9ca16c4abb3265046a9777fc668b96038cfd820b4
ep_bytes: 558bec81c4f0fbffff837d0c010f858e
timestamp: 2010-09-28 09:44:28

Version Info:

0: [No Data]

Trojan:Win32/Audhi.B also known as:

LionicTrojan.Win32.Hupigon.m!c
AVGWin32:MalwareX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.382082
FireEyeGeneric.mg.f245605ab44828f5
SkyhighGenericRXFE-LZ!F245605AB448
ALYacGen:Variant.Barys.382082
ZillyaBackdoor.Hupigon.Win32.110707
SangforBackdoor.Win32.Hupigon.Vrb6
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Hupigon.2f877249
K7GWTrojan ( 001f78e81 )
K7AntiVirusTrojan ( 001f78e81 )
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aejkEAj
VirITBackdoor.Win32.Hupigon5.BGOY
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Small.NIS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Hupigon-33548
KasperskyBackdoor.Win32.Hupigon.sbbe
BitDefenderGen:Variant.Barys.382082
NANO-AntivirusTrojan.Win32.Hupigon.cagqk
AvastWin32:MalwareX-gen [Trj]
TencentHackTool.Win32.FakeDll.f
TACHYONBackdoor/W32.Hupigon.3611.C
SophosTroj/Agent-QVA
BaiduWin32.Trojan.Delf.l
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Pigeon1.13421
VIPREGen:Variant.Barys.382082
TrendMicroTROJ_AUDHI.SMIA
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Barys.382082 (B)
IkarusBackdoor.Win32.Hupigon
JiangminBackdoor/Hupigon.bfws
VaristW32/Trojan2.NLLN
AviraTR/Spy.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
MicrosoftTrojan:Win32/Audhi.B
XcitiumTrojWare.Win32.Small.NIS@39bve0
ArcabitTrojan.Barys.D5D482
ViRobotBackdoor.Win32.A.Hupigon.3816
ZoneAlarmBackdoor.Win32.Hupigon.sbbe
GDataGen:Variant.Barys.382082
GoogleDetected
AhnLab-V3Trojan/Win32.Hupigon.R1609
McAfeeGenericRXFE-LZ!F245605AB448
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Hupigon
Cylanceunsafe
PandaBck/Hupigon.LOK
TrendMicro-HouseCallTROJ_AUDHI.SMIA
RisingTrojan.DL.Win32.GenFxj.x (CLASSIC)
YandexTrojan.GenAsa!+mZ/gKdRKAQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Hupigon.SMTA!tr.bdr
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Hupigon.sbbe

How to remove Trojan:Win32/Audhi.B?

Trojan:Win32/Audhi.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment