Malware

How to remove “MBR:Plite-I [Rtk]”?

Malware Removal

The MBR:Plite-I [Rtk] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MBR:Plite-I [Rtk] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine MBR:Plite-I [Rtk]?


File Info:

name: 44FA6A7DF28EA313D21F.mlw
path: /opt/CAPEv2/storage/binaries/48a70ee538be6fce081490fcfc2cc878be4f1ce91f72a0b54ce8c508f765659d
crc32: 6D1681EC
md5: 44fa6a7df28ea313d21f0acfc3f4ddab
sha1: 2a0f93039a0c8d22b3660135d690d6f6e99419ee
sha256: 48a70ee538be6fce081490fcfc2cc878be4f1ce91f72a0b54ce8c508f765659d
sha512: 75acce87413c3cfd61f2c9e89c656a13dace6ce228fd131104e8acc3dd0a977b4a43a40ffafeb6fd28b98ec2bf10e21c727de0c2460fe8540392e3b8eed0b786
ssdeep: 3072:NdXi+V5Kgxpdxj8gbib20xTyst542t8ZHWBow8+zoB91wDQgJl0x2AEMenKbZisd:Nd7rpL43btmQ58Z27zw39gY2FeZhTR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D774AD253580C435F72A07320446FAE40A66AC391A99E54FFBB8BD799D311978B3B24F
sha3_384: 3236745a207cc931fb30f363a04669a591fbb55a4aadea2b59bc4deaf3e23c36d1894c97090fc226732ca940f21c7270
ep_bytes: e819690000e917feffff558bec81ec28
timestamp: 2013-07-31 13:17:07

Version Info:

0: [No Data]

MBR:Plite-I [Rtk] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47151606
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKD.47151606
CylanceUnsafe
ZillyaBackdoor.Plite.Win32.1532
K7AntiVirusBackdoor ( 0053e8561 )
K7GWTrojan ( 005326d31 )
Cybereasonmalicious.df28ea
CyrenW32/Urelas.E.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
ClamAVWin.Malware.Urelas-9883246-0
KasperskyBackdoor.Win32.Plite.bhtx
BitDefenderTrojan.GenericKD.47151606
NANO-AntivirusTrojan.Win32.Plite.elodln
SUPERAntiSpywareBackdoor.Plite/Variant
AvastMBR:Plite-I [Rtk]
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
Ad-AwareTrojan.GenericKD.47151606
SophosML/PE-A + Troj/Urelas-Q
ComodoTrojWare.Win32.Urelas.ASE@5izxb0
DrWebTrojan.AVKill.32444
VIPRETrojan.Win32.Urelas.ab (v)
McAfee-GW-EditionBehavesLike.Win32.Corrupt.fh
FireEyeGeneric.mg.44fa6a7df28ea313
EmsisoftTrojan.GenericKD.47151606 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47151606
JiangminBackdoor.Generic.zin
AviraHEUR/AGEN.1123985
Antiy-AVLTrojan/Generic.ASMalwS.1E3A469
ArcabitTrojan.Generic.D2CF79F6
MicrosoftTrojan:Win32/Urelas.AA
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Plite.R444741
Acronissuspicious
McAfeeCorrupt-FY!44FA6A7DF28E
MAXmalware (ai score=86)
VBA32Backdoor.Plite
MalwarebytesTrojan.Urelas
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!TRw7gXDJu0U
eGambitUnsafe.AI_Score_99%
FortinetW32/Urelas.O!tr
BitDefenderThetaGen:NN.ZexaF.34294.uyXbaGdy6PmO
AVGMBR:Plite-I [Rtk]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove MBR:Plite-I [Rtk]?

MBR:Plite-I [Rtk] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment