Trojan

TrojanDropper:Win32/RedPlug.A!dha removal guide

Malware Removal

The TrojanDropper:Win32/RedPlug.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/RedPlug.A!dha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: PlugX
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/RedPlug.A!dha?


File Info:

name: 01468A69CA8676B51A35.mlw
path: /opt/CAPEv2/storage/binaries/fcccc611730474775ff1cfd4c60481deef586f01191348b07d7a143d174a07b0
crc32: B5CCD729
md5: 01468a69ca8676b51a357676e0856c88
sha1: 4413a7f864255767a6d84c3e8362b9873a7e224b
sha256: fcccc611730474775ff1cfd4c60481deef586f01191348b07d7a143d174a07b0
sha512: d0d516c96c14e4ec5dded82e80f82a3ff6b2f8c2aae63b8f0e8667aea6e07e52e8dcf2ee7939304ef2303b07a4b8ca6e6c64f985a508d57aad79440d479d68b8
ssdeep: 49152:Na175O/mZxrkaH1EN5/yxnxEil7F8vSZBWwj186KQGwi38KQrF+FO7p1FzohbJqE:uO/mZxbHW7yxnxECF8vSZBW+Pbi38KQU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D995AE307691C47BC2B331308B0AE779B2BEED708AB6114756916E3C7E74493992C76B
sha3_384: ecbec5b094d9080bb95fa23de80d0ffb2ff305b4876d291b338290264ab5711de64e1c1ae54f6049eac2e040fe88effe
ep_bytes: e8bbb00000e989feffff8bff558bec53
timestamp: 2016-11-10 02:15:14

Version Info:

FileVersion: 1, 0, 0, 1
InternalName: word
OriginalFilename: offcee.EXE
ProductName: offcee
ProductVersion: 1, 0, 0, 2
Translation: 0x1009 0x04b0

TrojanDropper:Win32/RedPlug.A!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Korplug.b!c
DrWebBackDoor.HRB.8
MicroWorld-eScanGen:Variant.Doina.13042
SkyhighBehavesLike.Win32.Dropper.th
McAfeeTrojan-PlugX!01468A69CA86
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Doina.13042
SangforDropper.Win32.Korplug.Vcm7
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Korplug.db12c05d
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Doina.D32F2
BitDefenderThetaGen:NN.ZexaF.36680.9v0@auh4DUej
VirITBackdoor.Win32.HRB.I
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Korplug.JJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.PlugX-6845045-0
KasperskyUDS:Trojan-Dropper.Win32.Injector.sb
BitDefenderGen:Variant.Doina.13042
NANO-AntivirusTrojan.Win32.Waldek.ejcorq
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114a6483
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Inject.gqnac
ZillyaTrojan.Korplug.Win32.878
TrendMicroBKDR_PLUGX.DUKPU
EmsisoftGen:Variant.Doina.13042 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Waldek.exq
WebrootW32.Trojan.Gen
AviraTR/AD.Inject.gqnac
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.APT10
Kingsoftmalware.kb.a.955
XcitiumMalware@#20vg8gwk4knyn
MicrosoftTrojanDropper:Win32/RedPlug.A!dha
ViRobotTrojan.Win32.S.Agent.2052608
ZoneAlarmUDS:Trojan-Dropper.Win32.Injector.sb
GDataGen:Variant.Doina.13042
GoogleDetected
AhnLab-V3Trojan/Win32.Waldek.C1789469
VBA32Backdoor.HRB
TACHYONTrojan/W32.Waldek.2052608
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallBKDR_PLUGX.DUKPU
RisingTrojan.Korplug!8.3EA (TFE:5:k9PZnp4AERU)
IkarusTrojan.Win32.Korplug
MaxSecureTrojan.Malware.10246069.susgen
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDropper:Win32/RedPlug.A!dha?

TrojanDropper:Win32/RedPlug.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment