Backdoor

About “Backdoor:Win32/Plugx” infection

Malware Removal

The Backdoor:Win32/Plugx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Plugx virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Plugx?


File Info:

crc32: A66B26B7
md5: 599b6e05a38329081b80a461b57cec37
name: 599B6E05A38329081B80A461B57CEC37.mlw
sha1: 2c4d72f47165bfd207d6c52f1bf5ab4fd1c27513
sha256: e52b87d95794977261728f9a25c3f59df86a3a7246f7607fbb1fbf9a0e85631d
sha512: abcf61dc194ab7d4f8bb8ebbbb98f3a3dfca79cae5a9528a2f27e604974519a5379d867efe4f4b0f79960d9aee4328d44bb40d120bb06a1c2b91b09c7438eba2
ssdeep: 24576:pAT8QE+kwjj/yDWVVBdx9wkqcY1jV7ZE0w5xLATNUrhwSnQtnwCet4EWPAm/JW5E:pAI+L/yiVVBDNYjmRrbO64LPAmxWO+2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Adobe
FileDescription: NewProduct 2.0.0.46 Installation
FileVersion: 2.0.0.46
Comments:
CompanyName: Adobe
Translation: 0x0409 0x04e4

Backdoor:Win32/Plugx also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004cee0a1 )
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.35772376
CylanceUnsafe
SangforBackdoor.Win32.Plugx.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Bookworm.c42780ad
K7GWTrojan ( 004cee0a1 )
Cybereasonmalicious.5a3832
CyrenW32/Plugx.PXXX-2209
SymantecBackdoor.Surge
ESET-NOD32Win32/Korplug.FQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Bookworm-6
KasperskyBackdoor.Win32.Bookworm.p
BitDefenderTrojan.GenericKD.35772376
NANO-AntivirusTrojan.Win32.Korplug.dwrjam
MicroWorld-eScanTrojan.GenericKD.35772376
TencentWin32.Backdoor.Bookworm.Sxot
Ad-AwareTrojan.GenericKD.35772376
SophosML/PE-A
ComodoMalware@#1mcf0rhliof8l
BitDefenderThetaGen:NN.ZedlaF.34628.aq4@a8SFBNe
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_PLUGX.DUKOI
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.599b6e05a3832908
EmsisoftTrojan.GenericKD.35772376 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Korplug.b
WebrootW32.Trojan.Gen
AviraTR/Korplug.4608.12
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Plugx
AegisLabTrojan.Win32.VB.ljzZ
GDataTrojan.GenericKD.35772376
TACHYONBackdoor/W32.DP-Bookworm.1657119
AhnLab-V3Trojan/Win32.PlugX.C1246892
McAfeeArtemis!599B6E05A383
MAXmalware (ai score=100)
VBA32Trojan.Korplug
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_PLUGX.DUKOI
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan.Win32.Korplug
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Bookworm.CO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HgIASOYA

How to remove Backdoor:Win32/Plugx?

Backdoor:Win32/Plugx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment