Threat Search: 

ThreatExpert's Statistics for BackDoor-AWQ.b [McAfee]:

BackDoor-AWQ.b [McAfee] is also known as:
Threat AliasNumber of Incidents
Backdoor.Graybird [Symantec]1,100
Backdoor:Win32/Hupigon [Microsoft]487
Backdoor.Hupigon.GEN [PC Tools]336
Backdoor.Hupigon!sd5 [PC Tools]292
BKDR_HUPIGON.GEN [Trend Micro]285
Backdoor.Win32.Hupigon.emb [Kaspersky Lab]276
Backdoor.Trojan [Symantec]233
Backdoor.Win32.Hupigon.avg [Kaspersky Lab]196
BKDR_HUPIGON.BRH [Trend Micro]196
VirTool.Win32.DelfInject [Ikarus]187
Backdoor.Win32.Hupigon [Ikarus]183
Mal/EncPk-AP [Sophos]169
Backdoor.Win32.Hupigon.cdc [Kaspersky Lab]145
Troj/GrayBrd-CQ [Sophos]145
Backdoor.Hupigon.AKGE [PC Tools]144
Backdoor.Win32.Hupigon.avh [Kaspersky Lab]144
Virus.Win32.AutoRun.k [Kaspersky Lab]132
BKDR_HUPIGON.CVT [Trend Micro]128
Packed.Win32.NSAnti.b [Kaspersky Lab]123
WORM_AGENT.SPS [Trend Micro]96
BKDR_HUPIGON.PW [Trend Micro]84
TROJ_SPAMBOT.B [Trend Micro]72
Mal/Generic-A [Sophos]67
Mal/Behav-053 [Sophos]64
Win-Trojan/Hupigon.56832.D [AhnLab]60
Backdoor.Hupigon [PC Tools]57
Win-Trojan/Hupigon.591360.CH [AhnLab]57
Backdoor.Bifrose.FOL [PC Tools]56
Mal/DSpy-B [Sophos]56
Win-Trojan/Hupigon.52736.M [AhnLab]56
Backdoor.Agent.ADIO [PC Tools]48
Backdoor.Win32.Hupigon.dsx [Kaspersky Lab]37
MalwareScope.Backdoor.Hupigon.5 [Ikarus]36
W32/Colit-A [Sophos]36
Worm.Win32.AutoRun.yq [Kaspersky Lab]36
Troj/GrayBrd-CD [Sophos]33
VirTool:Win32/DelfInject.gen!L [Microsoft]33
Backdoor.Graybird!Gen [Symantec]32
Trojan.Patched.BH [Ikarus]31
Backdoor.Win32.Hupigon.fwhy [Kaspersky Lab]30
Troj/Agent-HIP [Sophos]30
Virus.Win32.Hupigon.EA [Ikarus]29
Generic.dx [McAfee]27
Trojan Horse [Symantec]26
MalwareScope.Backdoor.Hupigon [Ikarus]25
Win-Trojan/Hupigon.287744.CH [AhnLab]25
Win-Trojan/Hupigon.61440.O [AhnLab]24
BKDR_HUPIGON.EWE [Trend Micro]23
Mal/Packer [Sophos]23
Backdoor.Win32.Hupigon.axbr [Kaspersky Lab]22
Win-Trojan/Hupigon.698368.D [AhnLab]22
Backdoor.Hupigon!sd6 [PC Tools]20
BKDR_HUPIGON.ABU [Trend Micro]20
Win-Trojan/Xema.variant [AhnLab]20
Trojan.Dropper [Symantec]19
Virus.Win32.Hupigon.AMD [Ikarus]18
Adware.Agent.ZTL [PC Tools]17
Troj/BHODLL-C [Sophos]16
Backdoor.Graybird.GEN [PC Tools]15
Backdoor:Win32/Yewbmoat.gen [Microsoft]15
Mal/Behav-058 [Sophos]15
VirTool:Win32/DelfInject.gen!X [Microsoft]15
not-a-virus:AdWare.Win32.BHO.bnb [Kaspersky Lab]14
Backdoor.Win32.Hupigon.eqzg [Kaspersky Lab]12
Downloader [Symantec]12
Trojan-PWS.Win32.QQPass [Ikarus]12
VirTool:Win32/DelfInject [Microsoft]12
W32.Koobface.A [Symantec]12
Win32/Autorun.worm.5120 [AhnLab]12
Win-Trojan/Hupigon.12024764 [AhnLab]12
Win-Trojan/Hupigon.761344.B [AhnLab]12
WORM_AUTORUN.SA [Trend Micro]12
Backdoor.Win32.HacDef.073.B [Ikarus]11
Backdoor:Win32/Hupigon.gen!B [Microsoft]11
Trojan-Dropper.Delf [Ikarus]11
Backdoor:Win32/Poison.Y [Microsoft]10
not-a-virus:AdWare.Win32.BHO [Ikarus]10
Win-Trojan/Hupigon.Gen [AhnLab]10
Backdoor.Graybird.K [Symantec]9
Backdoor.Win32.Hupigon.ffs [Kaspersky Lab]9
Backdoor.Win32.VB.jrm [Kaspersky Lab]9
Backdoor:Win32/Hupigon.gen [Microsoft]9
BKDR_HUPIGON.ALU [Trend Micro]9
BKDR_HUPIGON.IX [Trend Micro]9
TROJ_AGENT.ALKB [Trend Micro]9
Worm.AutoRun!sd6 [PC Tools]9
Backdoor.Graybird!sd6 [PC Tools]8
Backdoor.Hupigon.A!ct [PC Tools]8
Troj/CDur-Gen [Sophos]8
BKDR_HUPIGON.EVG [Trend Micro]7
BKDR_HUPIGON.FVR [Trend Micro]7
Infostealer.Gampass [Symantec]7
Mal/Emogen-N [Sophos]7
Trojan:Win32/Tibs.IT [Microsoft]7
Trojan-Downloader.Win32.Delf.aup [Ikarus]7
Trojan-Dropper.Agent [Ikarus]7
TrojanDropper:Win32/Delf.DV [Microsoft]7
W32.SillyFDC [Symantec]7
Backdoor [Ikarus]6
Backdoor.Rbot [Ikarus]6

BackDoor-AWQ.b [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China233
United Kingdom7
Russian Federation4
Brazil3
Taiwan2
Finland1
Germany1
Netherlands1
Switzerland1

BackDoor-AWQ.b [McAfee] is known to be created as:
%CommonFavorites%\beos.exe
%ProgramFiles%\_1.exe
%ProgramFiles%\_program.exe
%ProgramFiles%\_servicas.exe
%ProgramFiles%\_wmplayer.exe
%ProgramFiles%\360tray.exe
%ProgramFiles%\common files\snss.exe
%ProgramFiles%\entvip2008\kavservs.dll
%ProgramFiles%\entvip2008\kavservskey.dll
%ProgramFiles%\gene6 ftp server\g6ftptray.exe
%ProgramFiles%\hgzserver\g_server2006.dll
%ProgramFiles%\hgzserver\g_server2006key.dll
%ProgramFiles%\hgzuerver\hacker.com.cn.exe
%ProgramFiles%\iets.exe
%ProgramFiles%\internet explorer\connection wizard\inetwz.exe
%ProgramFiles%\internet explorer\svchosi.exe
%ProgramFiles%\internet explorer\svchost.dll
%ProgramFiles%\internet explorer\svchostkey.dll
%ProgramFiles%\java\javs.exe
%ProgramFiles%\ltass.exe
%ProgramFiles%\malwareremoval\malwareremoval.exe
%ProgramFiles%\meteors\svchost.dll
%ProgramFiles%\meteors\svchostkey.dll
%ProgramFiles%\microsoft common\wuauclt.exe
%ProgramFiles%\opremovba_chs1.exe
%ProgramFiles%\outlook express\ghost.exe
%ProgramFiles%\program.exe
%ProgramFiles%\remote\remote.exe
%ProgramFiles%\remote\systems.exe
%ProgramFiles%\servicas.exe
%ProgramFiles%\virusremover2008\pp.exe
%ProgramFiles%\windows media player\wmpen.exe
%ProgramFiles%\windows media player\wmpnetwk.exe
%ProgramFiles%\winrar\unrar.exe
%ProgramFiles%\winrar\winrarsyt.exe
%System%\_rejoice44.exe
%System%\_scvhost.exe
%System%\_usb.exe
%System%\_wins.exe
%System%\ati.exe
%System%\beal.exe
%System%\brc_server.exe
%System%\c2c.dll
%System%\dllhosts.exe
%System%\dnscon70.dll
%System%\drivers\etc\2ozqlgcg.dll
%System%\drivers\etc\5pfpy5rd.dll
%System%\drivers\etc\fnymtudl.dll
%System%\drivers\etc\jpgx4nuc.dll
%System%\drivers\etc\md1qjgla.dll
%System%\drivers\etc\shalvj3t.dll
%System%\drivers\etc\srlnub5p.dll
%System%\drivers\etc\ud3zixwb.dll
%System%\drivers\etc\xwac6hnz.dll
%System%\drivers\etc\zkldzquv.dll
%System%\ieupdate.dll
%System%\install.exe
%System%\kav.exe
%System%\ly_server2008.dll
%System%\ly_server2008key.dll
%System%\msbxg.dll
%System%\msbxkig.dll
%System%\nddend26.dll
%System%\netservice.exe
%System%\object.exe
%System%\oobe\html\mouse\osd\netsign.exe
%System%\ras\rassrv.dll
%System%\re008.exe
%System%\regsvcs.exe
%System%\retry.exe
%System%\safetray.exe
%System%\server.exe
%System%\servles.exe
%System%\splm\lmfunit32.dll
%System%\splm\mcaserv32.dll
%System%\splm\ncsjapi32.exe
%System%\svch0st.exe
%System%\svchst.exe
%System%\svckey.dll
%System%\svsh0st.exe
%System%\sy.dll
%System%\system32.exe
%System%\syswin.exe
%System%\temp1.exe
%System%\upcs.exe
%System%\vmware.exe
%System%\waysver.exe
%System%\windosff.dll
%System%\window.exe
%System%\windows.exe
%System%\winexecs.exe
%System%\winrar.exe
%System%\winsys32.exe
%System%\wintemp.exe
%System%\workstation.dll
%System%\xunleibho_001.dll
%System%\xydzyh.exe
%Temp%\14.exe
%Temp%\first.k.exe
%Temp%\ixp000.tmp\11.exe
Notes:
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).