Backdoor

Backdoor.Win32.Plite.bhsv malicious file

Malware Removal

The Backdoor.Win32.Plite.bhsv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhsv virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Plite.bhsv?


File Info:

name: A2A317BF6D124E70CA3B.mlw
path: /opt/CAPEv2/storage/binaries/71687d33f21d48f33c4e442bb57e3f8dcd7d157926a6ac5528a01f5ae75d662a
crc32: CEFAAD58
md5: a2a317bf6d124e70ca3bb76938dac5cc
sha1: 0a1fbdd96d957e81838177f201ed8af38369e6e6
sha256: 71687d33f21d48f33c4e442bb57e3f8dcd7d157926a6ac5528a01f5ae75d662a
sha512: 3eb6a72b680d6541385619d6ac9cfaa69fd623a504e343e761c2f460686eceaf1a74173e936421c4bf6362049ee1b718f6a63143aaf6d2e12b120f9d0f94c73f
ssdeep: 1536:Q2IzJdvRNtIBc6oSCv1WMW/3Gk5cTersWjcdK6UyfKM:QvHC9C9WZvnqeUK6UyfKM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127B35C00B7D1C076D0690B3148E49B214A7EFD325BA58D9BB7D4A24ECD346D0BE36B7A
sha3_384: c54aa27caad25a2a63a4b54c523c5378c970e454bab89f2333d420c4411c1c1883ddf6989d858402f56fbc7497898ede
ep_bytes: e8df5c0000e97ffeffff558bec5633f6
timestamp: 2014-11-05 06:29:38

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhsv also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.a2a317bf6d124e70
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePWS-FDJS!A2A317BF6D12
CylanceUnsafe
VIPREGen:Heur.Mint.SP.Urelas.1
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f6d124
BaiduWin32.Trojan.Urelas.b
CyrenW32/S-07a5605a!Eldorado
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.AE
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
KasperskyBackdoor.Win32.Plite.bhsv
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Dwn.dgxfhb
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosML/PE-A + Troj/Urelas-Q
ComodoTrojWare.Win32.Urelas.SEE@5443e3
DrWebTrojan.DownLoader11.30531
ZillyaBackdoor.Plite.Win32.21414
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.afyw
GoogleDetected
AviraBDS/Backdoor.Gen7
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.2482
MicrosoftTrojan:Win32/Urelas.AA
GDataWin32.Trojan.PSE.12K4ISD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R467822
Acronissuspicious
BitDefenderThetaAI:Packer.51435FBC1F
VBA32SScope.Backdoor.Urelas.3114
MalwarebytesUrelas.Spyware.Stealer.DDS
RisingTrojan.Urelas!1.BE13 (CLASSIC)
YandexBackdoor.Plite!u5PnVxzXYiw
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor.Win32.Plite.bhsv?

Backdoor.Win32.Plite.bhsv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment