Backdoor

What is “UDS:Backdoor.Win32.Plite”?

Malware Removal

The UDS:Backdoor.Win32.Plite is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Backdoor.Win32.Plite virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the EnigmaStub malware family
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:Backdoor.Win32.Plite?


File Info:

name: 639FA50DE3B931E98A44.mlw
path: /opt/CAPEv2/storage/binaries/d9277a069231b2d4147ea2d4a9d4f43200cde6ffc7435aa4a7bc96c241cacc6b
crc32: 015BA4B7
md5: 639fa50de3b931e98a445122e2b699f1
sha1: 3c2deda657aa5c811190fe4b76d3c51d54df0f24
sha256: d9277a069231b2d4147ea2d4a9d4f43200cde6ffc7435aa4a7bc96c241cacc6b
sha512: 33255324397b86a87847136195994a7aeab4d1f342ef96599ed4013c4da8976e3dbafefaca62ddb1929b5a4f35a1727e3029146a87cb789ae420dcaef7a5edc7
ssdeep: 49152:wa7g3ubqi5lAKMtusveFtyy1uRb5qNdVACJsGfI2CBxLKtgzWFoM:97BqiLMMsstyqIqNdi2FfI2646zWFN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14ED5331856065824F7AD2736E869F9E24411AD3CA0D5F9CEE47CFE322B346436A271CF
sha3_384: 2e7eb5ce1c3346d20978d9d704bd2415df5725a8b6b994524ef234be3281a1817dbb4995850ff9f2eaa7e676f35d6b9b
ep_bytes: eb08008608000000000060e800000000
timestamp: 2013-10-16 00:31:10

Version Info:

0: [No Data]

UDS:Backdoor.Win32.Plite also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.639fa50de3b931e9
SkyhighBehavesLike.Win32.Corrupt.vc
McAfeeArtemis!639FA50DE3B9
Cylanceunsafe
VIPRETrojan.GenericKD.71937932
SangforSuspicious.Win32.Save.ins
AlibabaBackdoor:Win32/Urelas.27f0821c
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D449AF8C
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win64/Packed.Enigma.CE
APEXMalicious
ClamAVWin.Trojan.Urelas-10024074-0
KasperskyUDS:Backdoor.Win32.Plite
BitDefenderTrojan.GenericKD.71937932
NANO-AntivirusTrojan.Win32.AVI.kkuxqh
MicroWorld-eScanTrojan.GenericKD.71937932
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10bfbde3
EmsisoftTrojan.GenericKD.71937932 (B)
F-SecureBackdoor.BDS/AVI.Urelas.vpknt
ZillyaBackdoor.Plite.Win32.114179
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win64.Enigma
GoogleDetected
AviraBDS/AVI.Urelas.vpknt
Antiy-AVLTrojan[Packed]/Win64.Enigma
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmUDS:Backdoor.Win32.Plite
GDataTrojan.GenericKD.71937932
AhnLab-V3Trojan/Win.Generic.R639988
BitDefenderThetaGen:NN.ZexaF.36802.QMY@a8FLgDbO
ALYacTrojan.GenericKD.71937932
MAXmalware (ai score=84)
VBA32SScope.Backdoor.Gulf
MalwarebytesUrelas.Trojan.Downloader.DDS
ZonerProbably Heur.ExeHeaderL
RisingBackdoor.Plite!8.2D6 (CLOUD)
SentinelOneStatic AI – Malicious PE
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Packed.EnigmaProtector.Z(dyn)

How to remove UDS:Backdoor.Win32.Plite?

UDS:Backdoor.Win32.Plite removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment