Backdoor

How to remove “Plead.Backdoor.Bot.DDS”?

Malware Removal

The Plead.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Plead.Backdoor.Bot.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the TSCookie malware family
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Plead.Backdoor.Bot.DDS?


File Info:

name: 55CF79BFD02B0CF36A52.mlw
path: /opt/CAPEv2/storage/binaries/17f1996ad7e602bd2a7e9524d7d70ee8588dac51469b08017df9aaaca09d8dd9
crc32: B161FDDF
md5: 55cf79bfd02b0cf36a524e7b813b686b
sha1: aec7648baac16b12c88e93e7320cb6d18ea214b1
sha256: 17f1996ad7e602bd2a7e9524d7d70ee8588dac51469b08017df9aaaca09d8dd9
sha512: 253bf38184e9033810f39054e2f71789e15828f5327d00a55209e9995a974f765ec07f07cd8dcb5c1ef6714a8af5259ca53f6d64a158bd1ec33d4ba1125bfe79
ssdeep: 3072:9+dDxQtIjMvFsnm2Ez8ZwDlnKKBGl/XeyfGGGGGG/pBzIilmOII:CQI4vGBZzKBGpVGGGGGGhB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E274BF5BB6E080BBD4AB35310DEA5671A775FD784F2326176380FBCE0832D465B36226
sha3_384: e6ab14d631225c565f9d00428281d058ff0ca95cf5c247c7c5695ef654878b7daddad39c9c7a1ee55cd9da5661aa4a65
ep_bytes: 558bec6aff688817420068649b400064
timestamp: 2017-09-05 01:38:00

Version Info:

0: [No Data]

Plead.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.48021
FireEyeGen:Variant.Doina.48021
SkyhighBehavesLike.Win32.Worm.fc
ALYacTrojan.TSCookie.gen
MalwarebytesPlead.Backdoor.Bot.DDS
VIPREGen:Variant.Doina.48021
SangforTrojan.Win32.Agent.V42q
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Doina.48021
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.baac16
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Plead.D
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Harmony.esnhbb
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
SophosMal/Generic-S
DrWebTrojan.DownLoader25.30453
ZillyaTrojan.Generic.Win32.126537
TrendMicroTROJ_PLEAD.SMZTEG
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Doina.48021 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=99)
GDataGen:Variant.Doina.48021
JiangminTrojan.Generic.bhbzm
WebrootW32.Trojan.Plead
GoogleDetected
Antiy-AVLTrojan[APT]/Win32.Blacktech
Kingsoftmalware.kb.a.987
XcitiumMalware@#1zbzlno6dn5df
ArcabitTrojan.Doina.DBB95
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Harmony.A!dha
BitDefenderThetaGen:NN.ZexaF.36792.wqW@aiC9PRkm
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_PLEAD.SMZTEG
TencentWin32.Trojan.Agen.Njgl
IkarusTrojan.Win32.Plead
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Plead.Backdoor.Bot.DDS?

Plead.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment