Backdoor

Should I remove “Backdoor:Win32/Plugx.H”?

Malware Removal

The Backdoor:Win32/Plugx.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Plugx.H virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: PlugX
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Plugx.H?


File Info:

name: 4DD49174D6BC55910538.mlw
path: /opt/CAPEv2/storage/binaries/4d464f9def2276dac15d19ccf049b7c68642290bc0e345e06d4b6e9103fde9e6
crc32: F52C0635
md5: 4dd49174d6bc559105383bdf8bf0e234
sha1: f0c0975f349f12cdbd39e00b151df07cd82ecf7d
sha256: 4d464f9def2276dac15d19ccf049b7c68642290bc0e345e06d4b6e9103fde9e6
sha512: baee063036c0b394a9459a9e4b044d9f08f4825f7f24080011aaa23aebcf6ce10e241eb329ca2cbc3f04b2c871830bb756b3d7b8dfd37377ee9904455bce20dd
ssdeep: 3072:Yok4FeBAdxx360IHdXA2rWlou0+11lAjg:7CAjx329JrWyZ412
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175B30134A6AF4633E3EB51F4A53F064A253FAD30BE05AB1C9352187BFD10789649E247
sha3_384: 358745af96ca657947858b6d6a75e8896b9cffcb56ecd0f42a7fc7c3d907368a584f687115b6bc6b720d8fdcb27a9974
ep_bytes: 558bec83ec1ca100c0410033c58945fc
timestamp: 2013-11-04 07:31:34

Version Info:

CompanyName: Sysinternals
FileDescription: DebugView
FileVersion: 4.79
InternalName: Sysinternals Debug Output Viewer
LegalCopyright: Copyright © 1998-2012 Mark Russinovich
OriginalFilename: Dbgview.exe
ProductName: Sysinternals Debugview
ProductVersion: 4.79
Translation: 0x0409 0x04b0

Backdoor:Win32/Plugx.H also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gulpix.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ExplorerHijack.gy0@au0O1gmi
ClamAVWin.Trojan.Plugx-1
FireEyeGeneric.mg.4dd49174d6bc5591
McAfeeGenericRXAA-AA!4DD49174D6BC
Cylanceunsafe
VIPREGen:Trojan.ExplorerHijack.gy0@au0O1gmi
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Gulpix.59e5214d
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITBackdoor.Win32.Generic.CKBD
CyrenW32/Ransom.J.gen!Eldorado
SymantecBackdoor.Korplug!gm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Korplug.BS
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Gulpix.tu
BitDefenderGen:Trojan.ExplorerHijack.gy0@au0O1gmi
NANO-AntivirusTrojan.Win32.Gulpix.cqnjdm
AvastWin32:Agent-ASHL [Trj]
TencentMalware.Win32.Gencirc.1175a9aa
EmsisoftGen:Trojan.ExplorerHijack.gy0@au0O1gmi (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen5.64483
ZillyaBackdoor.Gulpix.Win32.37
TrendMicroBKDR_PLUGX.AS
McAfee-GW-EditionBehavesLike.Win32.Pate.cc
Trapminemalicious.high.ml.score
SophosTroj/Plugx-X
IkarusTrojan.Win32.Crypt
GDataGen:Trojan.ExplorerHijack.gy0@au0O1gmi
JiangminBackdoor.Gulpix.do
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Gulpix
XcitiumMalware@#2jnbjawfcv847
ArcabitTrojan.ExplorerHijack.EF82DC
ViRobotTrojan.Win32.Z.Gulpix.112128
ZoneAlarmBackdoor.Win32.Gulpix.tu
MicrosoftBackdoor:Win32/Plugx.H
GoogleDetected
AhnLab-V3Trojan/Win32.Korplug.C221776
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36250.gy0@au0O1gmi
ALYacBackdoor.PlugX.A
MAXmalware (ai score=100)
VBA32Backdoor.Gulpix
MalwarebytesMalware.AI.2673314783
PandaGeneric Malware
TrendMicro-HouseCallBKDR_PLUGX.AS
RisingBackdoor.Gulpix!8.3DA (TFE:5:kihLMQCYEOF)
YandexBackdoor.Gulpix!3NKRsez07BQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.6663761.susgen
FortinetW32/Gulpix.TU!tr.bdr
AVGWin32:Agent-ASHL [Trj]
Cybereasonmalicious.4d6bc5
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Plugx.H?

Backdoor:Win32/Plugx.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment