Backdoor

About “Backdoor.Win32.Plurox.ags” infection

Malware Removal

The Backdoor.Win32.Plurox.ags is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plurox.ags virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Slovenian
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
suportecsm.com.br

How to determine Backdoor.Win32.Plurox.ags?


File Info:

crc32: 03037499
md5: f0a37d89ddaa7f9a424ee0dad1317f1f
name: Suporte-CSM-.exe
sha1: 9793cfea1559bd1058334acb78036bbbfc33b826
sha256: 201eb79321079c436eea7708ff23499443856cb183aa010ffd23607ceb7d97b9
sha512: d92e8b4aca0863c734916cc6bcaf273e701e1411bbb3b5b5da0ad57fd12bb17484dc086da2b78f53bdca051c2ddaac83b09542034f10590ccf73040e6766d964
ssdeep: 12288:JgO2dfeAjYlVuEk/qBiTyoCAOuiSAM9loypr3j1iIUbpdXWA4:+O2JeAjYEEk/q2hvQIl5r9J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Plurox.ags also known as:

MicroWorld-eScanTrojan.GenericKD.34372784
FireEyeTrojan.GenericKD.34372784
CAT-QuickHealBackdoor.Plurox
McAfeeArtemis!F0A37D89DDAA
ZillyaBackdoor.Plurox.Win32.75
AegisLabTrojan.Win32.Plurox.m!c
BitDefenderTrojan.GenericKD.34372784
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyBackdoor.Win32.Plurox.ags
AlibabaBackdoor:Win32/Plurox.bae26563
RisingBackdoor.Plurox!8.10930 (CLOUD)
Ad-AwareTrojan.GenericKD.34372784
F-SecureBackdoor.BDS/Plurox.bzhbm
SophosMal/Generic-S
IkarusBackdoor.Plurox
JiangminBackdoor.Plurox.cx
AviraBDS/Plurox.bzhbm
MAXmalware (ai score=87)
Antiy-AVLTrojan[Backdoor]/Win32.Plurox
MicrosoftTrojan:Win32/Ymacco.AA20
ArcabitTrojan.Generic.D20C7CB0
ZoneAlarmBackdoor.Win32.Plurox.ags
GDataTrojan.GenericKD.34372784
ALYacTrojan.GenericKD.34372784
TACHYONBackdoor/W32.Plurox.572437
VBA32Backdoor.Plurox
TrendMicro-HouseCallTROJ_GEN.R06BH07HH20
TencentWin32.Backdoor.Plurox.Ebzv
FortinetW32/Plurox.AGS!tr.bdr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.268

How to remove Backdoor.Win32.Plurox.ags?

Backdoor.Win32.Plurox.ags removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment