Backdoor

Backdoor.Win32.Plite.bhuk removal

Malware Removal

The Backdoor.Win32.Plite.bhuk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhuk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Plite.bhuk?


File Info:

name: DEEC37D0F436339A9CBD.mlw
path: /opt/CAPEv2/storage/binaries/386c8e5c1119ebdd39efc1f732e21020ba262244befe26066de1d520946289dd
crc32: 63F3B682
md5: deec37d0f436339a9cbd643b7b86ff3a
sha1: da97b490228aeccb652bc8651331eaf8a1cee564
sha256: 386c8e5c1119ebdd39efc1f732e21020ba262244befe26066de1d520946289dd
sha512: 6327881e7a372585697208a8d3c624a41ae06b533c38cd8dca00c18322ebd6f5eef232182d1d1481114f3db18293e20c4f696d7cb6a05a08d3331662284243a9
ssdeep: 1536:plMHOr+GWy7duuniNoBc3YC9f/9MFMJ5suPeicjNWQ1sWjcd56U86RqjP2:bMHOrqCoDn9Ma3exf656U8rP2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FC35D00B2D1C030E0B54635069A9B21593DFD719BA94EDBB7C85D9ECA782C17A32FB7
sha3_384: 79bae84b520ca0c0b98eabb8ade60a19fd76d64e2699237b2bdf9927f52dd4f199103c1b93a7e03168b484fac6155c98
ep_bytes: e8e55c0000e97ffeffff558bec5633f6
timestamp: 2014-11-02 07:28:20

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhuk also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.DownLoader11.31668
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.deec37d0f436339a
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
VIPREGen:Heur.Mint.SP.Urelas.1
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.0f4363
BitDefenderThetaAI:Packer.7291CCE220
CyrenW32/S-07a5605a!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.AB
ClamAVWin.Malware.Urelas-6717394-0
KasperskyBackdoor.Win32.Plite.bhuk
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Plite.fxvepp
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Urelas.SEE@5443e3
BaiduWin32.Trojan.Urelas.b
ZillyaBackdoor.Plite.Win32.3676
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.127SQLG
JiangminBackdoor.Generic.atlc
AviraBDS/Backdoor.Gen7
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.2482
ZoneAlarmBackdoor.Win32.Plite.bhuk
MicrosoftTrojan:Win32/Urelas.AA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Urelas.R461505
McAfeeGenericRXAA-AA!DEEC37D0F436
VBA32SScope.Backdoor.Urelas.3114
MalwarebytesUrelas.Spyware.Stealer.DDS
APEXMalicious
RisingTrojan.Urelas!1.BE13 (CLASSIC)
YandexBackdoor.Plite!WvJQds+sgc0
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor.Win32.Plite.bhuk?

Backdoor.Win32.Plite.bhuk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment