Backdoor

What is “Backdoor.Win32.Plite.bhtq”?

Malware Removal

The Backdoor.Win32.Plite.bhtq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhtq virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Backdoor.Win32.Plite.bhtq?


File Info:

name: EF5F1073CB87D93548A7.mlw
path: /opt/CAPEv2/storage/binaries/3618676d19fda35ef959660a882635118a752d868f6e091fdac876e9340b1032
crc32: 1EDA6444
md5: ef5f1073cb87d93548a7d0f922a4789a
sha1: f538addd8222e121e22ffaf3ed7753af83d444cc
sha256: 3618676d19fda35ef959660a882635118a752d868f6e091fdac876e9340b1032
sha512: 11002b10bc07bb5ee0292ad9b1e9ba1784ab3e0805b31c1b55185ef40ad2a6769b1ff955d6d6f219f075c8f95bb4ef382bc862982e22e32dd5aefd8831437778
ssdeep: 12288:TeGtVfjTQSaoINAHT15lUSE0nF82EhLd1zXq2jb:TLt4/NA199a2Ed5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0C4AE1036908475F366273108A6E6F41AB97C384AA5E58FF7647E3A6E311D38A3734F
sha3_384: 783ba81c8933d5d6dd9f9ceb945145859837c1e2add7db8da14c46533d2363a68405821a5d563092d45d25b86b6e5728
ep_bytes: e83fa40000e979feffff8bff558bec51
timestamp: 2013-08-22 13:02:31

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhtq also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lKG1
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.32817
MicroWorld-eScanMemScan:Trojan.GenericKDZ.96040
CAT-QuickHealTrojan.Gupboot.G.mue
ALYacMemScan:Trojan.GenericKDZ.96040
MalwarebytesCardSpy.Spyware.Stealer.DDS
VIPREMemScan:Trojan.GenericKDZ.96040
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
AlibabaBackdoor:Win32/Urelas.2eb2
K7GWTrojan ( 0047e3691 )
Cybereasonmalicious.3cb87d
BitDefenderThetaGen:NN.ZexaF.36196.HmX@aig8nraO
CyrenW32/Urelas.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
ClamAVWin.Malware.Urelas-9655843-0
KasperskyBackdoor.Win32.Plite.bhtq
BitDefenderMemScan:Trojan.GenericKDZ.96040
NANO-AntivirusTrojan.Win32.Plite.cvbpsw
ViRobotTrojan.Win.Z.Urelas.549873.D
AvastMBR:Plite-I [Rtk]
TencentTrojan.Win32.Urelas.16000132
EmsisoftMemScan:Trojan.GenericKDZ.96040 (B)
F-SecureHeuristic.HEUR/AGEN.1317509
BaiduWin32.Rootkit.Agent.s
ZillyaTrojan.Urelas.Win32.42384
TrendMicroTROJ_GEN.R002C0DEK23
McAfee-GW-EditionBehavesLike.Win32.Corrupt.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ef5f1073cb87d935
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.110RWKI
JiangminBackdoor.Generic.zjt
AviraHEUR/AGEN.1317509
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Generic
XcitiumTrojWare.Win32.GupBoot.SEH@56eidq
ArcabitTrojan.Generic.D17728
ZoneAlarmBackdoor.Win32.Plite.bhtq
MicrosoftTrojan:Win32/Urelas.AA
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Plite.R141230
Acronissuspicious
McAfeeCorrupt-FY!EF5F1073CB87
VBA32Backdoor.Plite
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEK23
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.GenAsa!T9bs+ffsnlE
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.BN!tr
AVGMBR:Plite-I [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Plite.bhtq?

Backdoor.Win32.Plite.bhtq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment