Backdoor

Should I remove “Backdoor.Win32.Plite.bhti”?

Malware Removal

The Backdoor.Win32.Plite.bhti is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhti virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Win32.Plite.bhti?


File Info:

name: 5298C8C93249644B83C4.mlw
path: /opt/CAPEv2/storage/binaries/5ef37b43007950100d19bf6abd591a8320b2916fcc1943d3f8b5d564de842ece
crc32: F0691826
md5: 5298c8c93249644b83c496787c3d309d
sha1: 740d3abeeb937c58d60d550ecc27bf74af5cb66b
sha256: 5ef37b43007950100d19bf6abd591a8320b2916fcc1943d3f8b5d564de842ece
sha512: 1edda5a8dee1acea9d638e0e365e6543a61d25b100ffa6c38df027df77b26fd08f79fa292b6f6fb3312b987d409235a44c6ff16e409bff394ff8e43e184ff834
ssdeep: 24576:CwfNsYAmmAMPxwhtqY0hpNiSBObE6bopJNW:DsY4AMPif1SD8b7uW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D0523845F811D61F70E0BBA6D97F0A10A612FB9A5D9E19FE23279359CB724390B700F
sha3_384: 9351c1d2bd4460502d822079cfd965e047f38980d05b8d2490c5d871829d54286516a2c2a2f6a825bb8073dcd52831a3
ep_bytes: b8b0ea4d005064ff3500000000648925
timestamp: 2013-07-26 06:47:37

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhti also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.98150
ClamAVWin.Trojan.Agent-1347755
FireEyeGeneric.mg.5298c8c93249644b
CAT-QuickHealTrojan.Gupboot.G.mue
McAfeeGenericRXAA-AA!5298C8C93249
Cylanceunsafe
ZillyaTrojan.Urelas.Win32.1074
SangforSuspicious.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
K7GWBackdoor ( 0053e8561 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.SHeur4.CFDA
CyrenW32/Coxy.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhti
BitDefenderTrojan.GenericKDZ.98150
NANO-AntivirusTrojan.Win32.Plite.ekcbje
AvastWin32:Dropper-gen [Drp]
TencentTrojan.Win32.Urelas.16000132
EmsisoftTrojan.GenericKDZ.98150 (B)
F-SecureBackdoor.BDS/Backdoor.Gen7
DrWebTrojan.AVKill.32443
VIPRETrojan.GenericKDZ.98150
McAfee-GW-EditionBehavesLike.Win32.Corrupt.cc
SophosTroj/Urelas-Q
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.98150
JiangminBackdoor.Generic.zjq
AviraBDS/Backdoor.Gen7
Antiy-AVLTrojan[Rootkit]/Win32.Plite
XcitiumTrojWare.Win32.Small.NAF@531prv
ArcabitTrojan.Generic.D17F66
ZoneAlarmBackdoor.Win32.Plite.bhti
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Urelas.R76116
Acronissuspicious
VBA32BScope.Trojan.AVKill
ALYacTrojan.GenericKDZ.98150
MAXmalware (ai score=86)
MalwarebytesAgent.Trojan.DDOS.DDS
PandaTrj/Genetic.gen
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexBackdoor.Agent!o8f2XjmxZ7c
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.BN!tr
BitDefenderThetaGen:NN.ZelphiF.36164.0mXfaSDJs!eO
AVGWin32:Dropper-gen [Drp]
DeepInstinctMALICIOUS

How to remove Backdoor.Win32.Plite.bhti?

Backdoor.Win32.Plite.bhti removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment