Backdoor

Backdoor.Win32.Plite.bhui removal guide

Malware Removal

The Backdoor.Win32.Plite.bhui is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhui virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Plite.bhui?


File Info:

name: 706DD459C0363958BF74.mlw
path: /opt/CAPEv2/storage/binaries/9f40422c15010f82f06228e34ea58ca549026f28d5b1785b517d296b8b2f79bf
crc32: C0FA649C
md5: 706dd459c0363958bf74b6d969e39b81
sha1: a1b1d807a57451d3613184cb56b5f62a603ef7ee
sha256: 9f40422c15010f82f06228e34ea58ca549026f28d5b1785b517d296b8b2f79bf
sha512: 3ee505b93329af5a0aa9549d2ae1960a8ac75fc5d8ca363ca0e82d861963f38c72ef274b0330cbbcb9cc8c226f28bee36efc910314d0a9c9840d86b87519007b
ssdeep: 6144:dYPHxZjacj40fBnQPVe9ws3xpeT8UhD4p5GGpaIz6haxe6KOdhTifHkEpcE:dYPRZGcj40pnyawshpe4UhDk8Muye6K3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13474F1266B004C64F79C0B312AA5F9E00599AC3D21E5F14FF4BCBD7669B158B2A3315F
sha3_384: ee9da03c983f550befded3f8d5625bede8013b265368884ea27242eea1d73dce00fd4cdca0bf8ab649509d546c01f325
ep_bytes: b824344b005064ff3500000000648925
timestamp: 2013-08-26 01:39:24

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhui also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.706dd459c0363958
CAT-QuickHealTrojan.Gupboot.G.mue
MalwarebytesMalware.AI.3471141186
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWBackdoor ( 0053e8561 )
Cybereasonmalicious.9c0363
BitDefenderThetaGen:NN.ZexaF.34712.vmXfaW3lsUbO
VirITTrojan.Win32.AVKill.BWJW
CyrenW32/Urelas.E.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.S
ClamAVWin.Trojan.Agent-1144222
KasperskyBackdoor.Win32.Plite.bhui
NANO-AntivirusTrojan.Win32.csgvga.eaqeap
SUPERAntiSpywareTrojan.Agent/Gen-Small
APEXMalicious
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosML/PE-A + Troj/Urelas-AA
ComodoTrojWare.Win32.Small.NAF@531prv
DrWebTrojan.AVKill.32704
ZillyaTrojan.Urelas.Win32.1426
McAfee-GW-EditionBehavesLike.Win32.Corrupt.fc
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
IkarusTrojan.Win32.Gupboot
JiangminBackdoor.Generic.zkh
AviraTR/Spy.Gen2
MicrosoftPWS:Win32/Zbot!ml
ArcabitTrojan.Mint.SP.Urelas.1
GDataGen:Heur.Mint.SP.Urelas.1
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Bootkit.357162
Acronissuspicious
McAfeeCorrupt-FY!7DDD80EA9001
MAXmalware (ai score=86)
VBA32Backdoor.Plite
CylanceUnsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Urelas.16000132
YandexTrojan.GenAsa!HHwxQQpNUng
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.O!tr
AVGMBR:Plite-I [Rtk]
AvastMBR:Plite-I [Rtk]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Plite.bhui?

Backdoor.Win32.Plite.bhui removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment