Trojan

Trojan:Win32/Plugx.B malicious file

Malware Removal

The Trojan:Win32/Plugx.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Plugx.B virus can do?

  • Authenticode signature is invalid

How to determine Trojan:Win32/Plugx.B?


File Info:

name: A12BADD0FE8FD8E1B4C4.mlw
path: /opt/CAPEv2/storage/binaries/c8e272df00b5cb4a1e4a2012bcde12c28ab32f61346b47bb775de7344e372b58
crc32: 47E99BC2
md5: a12badd0fe8fd8e1b4c46aa13e0889af
sha1: 8cca27d32dd9ce284444f30c857c510adc48910a
sha256: c8e272df00b5cb4a1e4a2012bcde12c28ab32f61346b47bb775de7344e372b58
sha512: a27c2a32247ab0a1d83f3d6322938c2e066674812d213e5d6a487819f20d18e552d91de88825b1c4d0c147eb2c13c810f5740a2a6a46619070bcd60e0a74cea1
ssdeep: 24:e1GSqBPHOeY1wHeXS8cw3/tIo0/shf5J4xLFmbvjY/B:SqBypXX3sI5JfbvjY/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1195165AB9B6B086BF0A40F328BC749D29BFE0A1336C7222FCF55054624D165D5988EB1
sha3_384: 8ea5fbf31e7396d4d670ddd8f9bdead07916e7d9927c398f730c2af8135f5b432a8d5144a4c875badefba18ff10b0aeb
ep_bytes: 8b442404a3003000108b442408487505
timestamp: 2012-06-07 10:44:45

Version Info:

0: [No Data]

Trojan:Win32/Plugx.B also known as:

LionicTrojan.Win32.Plugx.4!c
AVGWin32:PlugX-D [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.191034
FireEyeGen:Variant.Babar.191034
SkyhighBehavesLike.Win32.Generic.zz
McAfeeBackDoor-FBKF!A12BADD0FE8F
ZillyaTrojan.Korplug.Win32.2203
SangforTrojan.Win32.Plugx.V2sl
K7AntiVirusTrojan ( 003e27521 )
AlibabaTrojan:Win32/Plugx.d512f9b7
K7GWTrojan ( 003e27521 )
BitDefenderThetaGen:NN.ZedlaF.36804.au4@a4sogwhi
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Korplug.A
CynetMalicious (score: 100)
AvastWin32:PlugX-D [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Babar.191034
NANO-AntivirusTrojan.Win32.Plugx.damekc
TencentWin32.Trojan.Agen.Czlw
EmsisoftGen:Variant.Babar.191034 (B)
F-SecureHeuristic.HEUR/AGEN.1300782
VIPREGen:Variant.Babar.191034
TrendMicroTROJ_PLUGX.SMF
SophosTroj/Plugx-AP
IkarusTrojan.Plugx
AviraHEUR/AGEN.1300782
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.a.720
MicrosoftTrojan:Win32/Plugx.B
XcitiumMalware@#9imk5pbca8i1
ArcabitTrojan.Babar.D2EA3A
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Babar.191034
GoogleDetected
AhnLab-V3Backdoor/Win32.Etso.R25235
VBA32Heur.Trojan.Hlux
ALYacGen:Variant.Babar.191034
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_PLUGX.SMF
RisingTrojan.Generic@AI.82 (RDML:5h7qotYoGBvYUAdZUEYhCA)
YandexTrojan.GenAsa!h1RLQZR8rmY
MAXmalware (ai score=81)
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Korplug.A
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan:Win32/Plugx.B?

Trojan:Win32/Plugx.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment