Malware

Win32/Hupigon.NPI removal guide

Malware Removal

The Win32/Hupigon.NPI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Hupigon.NPI virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Hupigon.NPI?


File Info:

name: 79DCBD1256ACF1BA5A23.mlw
path: /opt/CAPEv2/storage/binaries/20527adbae00fb4117d5c11dc856790e909ed03bbe6d1d4a7a7ee701702419cd
crc32: 54486D80
md5: 79dcbd1256acf1ba5a23346a5d2307b1
sha1: 0b672e278f984b367c67c436d822ebf71cf77a4a
sha256: 20527adbae00fb4117d5c11dc856790e909ed03bbe6d1d4a7a7ee701702419cd
sha512: 7a829d0d217e465c53e03fde0bbd65aa8370e9b4e6f0baeab3578710edfac185cba8233a38b98c91e3dcfdcc9ccac31989667787acc0326fdae5b41113fe3ec0
ssdeep: 6144:v/nuowIOAHJStKU++eutpBv2Pgsr65okQ54vQiZDg/Rn7eIAk5NaeIPc4frCmp5s:vGEStU+eut1S6+FiQi5nk5NFIPsEq7r9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBB401A391C0C17AD0D883B1C5EA2DFB1A37ACB5D795029B92897DA33473081767E61F
sha3_384: f0abedf0ad71ea1c92fcb9161a11daf721f62605874fc2594859a0f8f8f4a35554c382ad43d392170706af88c95e8c28
ep_bytes: e9864e00009090909090cccccccccc8b
timestamp: 2008-01-25 18:05:51

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.3300 (xpsp.080125-2028)
InternalName: Wextract
LegalCopyright: (C) Microsoft Corporation. 保留所有权利.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.3300
Translation: 0x0804 0x04b0

Win32/Hupigon.NPI also known as:

tehtrisGeneric.Malware
FireEyeGeneric.mg.79dcbd1256acf1ba
McAfeeArtemis!79DCBD1256AC
MalwarebytesMalware.AI.3202505607
SangforBackdoor.Win32.Hupigon.frAYPE
K7AntiVirusTrojan ( 000015c51 )
K7GWTrojan ( 000015c51 )
Cybereasonmalicious.78f984
CyrenW32/SuspPack.AC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Hupigon.NPI
ClamAVWin.Trojan.Hupigon-6915215-0
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Hupigon.cekobb
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
ComodoMalware@#14nwy4z1lh787
F-SecureBackdoor.BDS/Hupigon.Gen
DrWebTrojan.Packed.551
McAfee-GW-EditionBackDoor-AWQ.gen.t
SentinelOneStatic AI – Suspicious SFX
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Frethog-B
APEXMalicious
JiangminBackdoor/Hupigon.ayjb
AviraBDS/Hupigon.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Heur.KVMH004.a.(kcloud)
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32SScope.Backdoor.Hupigon
CylanceUnsafe
RisingPacker.Win32.Agent.bd (CLASSIC)
YandexTrojan.Scar!Ya7KPz5VeBU
IkarusBackdoor.Hupigon
FortinetW32/Kryptik.KYT!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Hupigon.NPI?

Win32/Hupigon.NPI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment