Backdoor

Backdoor:Win32/Plugx!B (file analysis)

Malware Removal

The Backdoor:Win32/Plugx!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Plugx!B virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Plugx!B?


File Info:

crc32: DBFD46C9
md5: 0560b52f6229ee7c29243749241510b7
name: 0560B52F6229EE7C29243749241510B7.mlw
sha1: 3f8a3a9f7ab213eeba258448fd6076e4a9516b7d
sha256: 3cdd33dea12f21a4f222eb060e1e8ca8a20d5f6ca0fd849715f125b973f3a257
sha512: 3cca683ac4d12321de715801e26ca7214dcd33013879366d62688f8c0c551fbbfaca8350c4327c7b372597b0406e076983f8db3c9b72a46bc533f1e540f0926e
ssdeep: 3072:TXhd7tKQ6D6+or3Dnov39gyQ21MkBX+s+bd8wCnTFaEiTwuenMrk:NLKNDuTov39K21MkBX+Hd8wQiT8Mr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Plugx!B also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gulpix.m!c
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
ClamAVWin.Trojan.Plugx-9758632-0
CAT-QuickHealBackdoor.Gulpix
ALYacGen:Variant.Bulz.408223
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Gulpix.aa3d2eb7
ESET-NOD32a variant of Win32/Korplug.JM
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.Gulpix.xxm
BitDefenderGen:Variant.Bulz.408223
NANO-AntivirusTrojan.Win32.Korplug.feoqzs
ViRobotTrojan.Win32.Z.Korplug.245760
MicroWorld-eScanGen:Variant.Bulz.408223
TencentWin32.Backdoor.Gulpix.Eei
Ad-AwareGen:Variant.Bulz.408223
SophosMal/Generic-S
ComodoMalware@#3hz3oto0af4q5
F-SecureTrojan.TR/Korplug.jzvgh
BitDefenderThetaGen:NN.ZedlaF.34050.pq4@a0VsWYd
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DGN21
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.0560b52f6229ee7c
EmsisoftGen:Variant.Bulz.408223 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Gulpix.jj
AviraTR/Korplug.jzvgh
Antiy-AVLTrojan[Backdoor]/Win32.Gulpix
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Plugx.gen!B
ArcabitTrojan.Bulz.D63A9F
ZoneAlarmBackdoor.Win32.Gulpix.xxm
GDataGen:Variant.Bulz.408223
AhnLab-V3Malware/Win32.Generic.C2628772
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=88)
VBA32Backdoor.Gulpix
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGN21
YandexBackdoor.Gulpix!+t8OHyJHlpo
IkarusTrojan.Win32.Korplug
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Korplug.JM!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.PlugX.HgkASZEA

How to remove Backdoor:Win32/Plugx!B?

Backdoor:Win32/Plugx!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment