Backdoor

Should I remove “Backdoor.Win32.Plite.bhts”?

Malware Removal

The Backdoor.Win32.Plite.bhts is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhts virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Created a process from a suspicious location

How to determine Backdoor.Win32.Plite.bhts?


File Info:

name: 1EBA00E65C67F33754AF.mlw
path: /opt/CAPEv2/storage/binaries/cccc3f47dc6151a4bda0ea6ca0e8b894b9e67ea82b12b41ce7df860624316731
crc32: BE1599FD
md5: 1eba00e65c67f33754af29ce90cb3ab0
sha1: 3647e3627e97f8ee640bb26e9269363a1b8889a7
sha256: cccc3f47dc6151a4bda0ea6ca0e8b894b9e67ea82b12b41ce7df860624316731
sha512: 9a3fadbd616113daf8e21893a19d0a491406c139a40b88c27e26122e4e2a7bac43f8026dee0b0969b3f7dab84e64b2c58f91f1f64bc76e40ae02d7ee79051438
ssdeep: 6144:O64g0RlXb4xNEmoS+R68AuSXBGuaVBt7QwIiZQEszTnZzf:F4g0RCXoSO43x+l7QLiaEyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F64F11297100558F3684B392E6AF8E049989E3E54D5F6AFF4BCBC3B683169359B700F
sha3_384: 44d1feeb78ebd103f150d76048ee837440129593f965cc9805dc7c632246bd3980eecf2f84318125280b9ea684760091
ep_bytes: 60be006046008dbe00b0f9ff5789e58d
timestamp: 2013-10-05 10:52:28

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhts also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.33294
ClamAVWin.Trojan.Gupboot-3
FireEyeGeneric.mg.1eba00e65c67f337
CAT-QuickHealTrojan.Gupboot.G.mue
CylanceUnsafe
VIPRETrojan.Win32.Urelas.o (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 00588d7d1 )
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWSpyware ( 00588d7d1 )
Cybereasonmalicious.65c67f
BitDefenderThetaGen:NN.ZexaF.34212.tmHfaepDn4aO
VirITTrojan.Win32.SHeur4.CBMB
CyrenW32/Gupboot.B.gen!Eldorado
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/Urelas.T
TrendMicro-HouseCallTROJ_GUPBOOT_EJ13000F.UVPM
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhts
NANO-AntivirusTrojan.Win32.cndyab.eaawqp
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
RisingTrojan.Gupboot!1.9CEA (RDMK:cmRtazo8JsVfDBwKSvL13Qx8CgKm)
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosML/PE-A + Troj/Urelas-AA
ComodoTrojWare.Win32.Urelas.P@555slg
BaiduWin32.Trojan.Urelas.a
ZillyaTrojan.Swisyn.Win32.30683
TrendMicroTROJ_GUPBOOT_EJ13000F.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
GDataWin32.Trojan.Urelas.KLGTSP
JiangminTrojan/Swisyn.wmu
AviraTR/Spy.Gen2
MAXmalware (ai score=84)
SUPERAntiSpywareTrojan.Agent/Gen-Gupboot
ZoneAlarmBackdoor.Win32.Plite.bhts
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Backdoor/Win32.Plite.R238946
Acronissuspicious
McAfeeCorrupt-JB!1EBA00E65C67
VBA32BScope.Trojan.AVKill
MalwarebytesTrojan.Urelas
PandaTrj/Genetic.gen
APEXMalicious
TencentTrojan.Win32.Urelas.16000132
YandexTrojan.GenAsa!YDlJxQj3pmE
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetW32/Urelas.O!tr
AVGWin32:Dropper-NGS [Drp]
AvastWin32:Dropper-NGS [Drp]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove Backdoor.Win32.Plite.bhts?

Backdoor.Win32.Plite.bhts removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment