Backdoor

Backdoor:Win32/PlugX.AD!dha removal tips

Malware Removal

The Backdoor:Win32/PlugX.AD!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/PlugX.AD!dha virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • PlugX
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Created a service that was not started

Related domains:

www.flash.cn
api.flash.cn
data.ugliquarie.com
dlmping2.adobe.com
stats.adobe.com

How to determine Backdoor:Win32/PlugX.AD!dha?


File Info:

crc32: 5FF7098B
md5: a6518a38723b216e6ef553690065af80
name: A6518A38723B216E6EF553690065AF80.mlw
sha1: 11d4432b52bc4a4844641aaa3e8a3d426177647e
sha256: 02a76cee60decc4fb8b548f66b103495983a647acf60c5b2c1123351b0d4ea13
sha512: c76c1b05f9f6498e3453224f1d18549b7e20be2617c77b1f74103e0d8c9b9c5a54346053d9591322ad70eaa5d11cc2450e5f46e330dce02e91404717eb8b34ca
ssdeep: 49152:iXVcyHCq1bcuOuokh8ImIr/AngDlX1WqCV4HLHCq1bcuOuokh8ImIr/AngDlX1W:ilJHnThzm0/AgBgqU4rHnThzm0/AgBg
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright 2019 Adobe Inc. All rights reserved.
InternalName: Adobe Download Manager
FileVersion: 3.0.0.508s
CompanyName: Adobe Inc
ProductName: Adobe Download Manager
ProductVersion: 3.0.0.508s
FileDescription: Adobe Download Manager
OriginalFilename: Adobe Download Manager
Translation: 0x0409 0x04b0

Backdoor:Win32/PlugX.AD!dha also known as:

MicroWorld-eScanTrojan.GenericKD.45328183
FireEyeGeneric.mg.a6518a38723b216e
ALYacTrojan.GenericKD.45328183
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Gulpix.m!c
SangforMalware
K7AntiVirusTrojan ( 0053b9aa1 )
BitDefenderTrojan.GenericKD.45328183
K7GWTrojan ( 0053b9aa1 )
Cybereasonmalicious.8723b2
BitDefenderThetaGen:NN.ZemsilCO.34742.4o0@a8W4wZji
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R011C0DA821
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.Win32.Gulpix.gen
AlibabaBackdoor:Win32/PlugX.f9d69715
RisingPUF.2144FlashPlayer!8.1141E (TFE:4:GoA3bspPMiT)
Ad-AwareTrojan.GenericKD.45328183
SophosMal/Generic-R
ComodoMalware@#1rwbwrzpikxak
TrendMicroTROJ_GEN.R011C0DA821
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45328183 (B)
AviraTR/Korplug.nhrqr
MicrosoftBackdoor:Win32/PlugX.AD!dha
GridinsoftTrojan.Win32.Gen.oa
ArcabitTrojan.Generic.D2B3A737
ZoneAlarmHEUR:Backdoor.Win32.Gulpix.gen
GDataTrojan.GenericKD.45328183
CynetMalicious (score: 85)
McAfeeArtemis!A6518A38723B
MAXmalware (ai score=88)
VBA32Trojan.MSIL.gen.a.11
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32multiple detections
IkarusTrojan.Win32.Korplug
FortinetW32/Gulpix.AP!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.3a0

How to remove Backdoor:Win32/PlugX.AD!dha?

Backdoor:Win32/PlugX.AD!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment