Backdoor

VHO:Backdoor.Win32.Plite malicious file

Malware Removal

The VHO:Backdoor.Win32.Plite is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.Win32.Plite virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine VHO:Backdoor.Win32.Plite?


File Info:

name: D62447E35F1F7106CABA.mlw
path: /opt/CAPEv2/storage/binaries/07cf2db580b640fe1ee4247322b0fe3c6f7cac8910f6194fb49b277d8419dd2f
crc32: B2508E34
md5: d62447e35f1f7106caba9cda28834d74
sha1: 9c008a91caaaac1df6f2d3a08c0db16dc3be07e7
sha256: 07cf2db580b640fe1ee4247322b0fe3c6f7cac8910f6194fb49b277d8419dd2f
sha512: 91ef5ee1655955f19de572677218acd435c8c832d574597e9cd3924650cffe74360c75493df0f752c479133e24d8c8e97efeeb8d9bf521572b803870f7b22357
ssdeep: 12288:PuF8bTkfbPefdP5r6I/Vqpg7YJmmjXp+CZ:PZbTkfSfdPF6I/8aeTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17194CE4BFF235499F866F130206E97E28AAADC1041291623697DB115AC5A3BD0FF3DC7
sha3_384: 54320ed357b79efe53a34419d6c8a215275c592283b3629b475f2c75f7c5072f3edf3be1499df7550bf3a57aca25713a
ep_bytes: b83c9f46005064ff3500000000648925
timestamp: 2013-08-05 13:59:55

Version Info:

0: [No Data]

VHO:Backdoor.Win32.Plite also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.d62447e35f1f7106
CAT-QuickHealTrojan.Bulta.B3
CylanceUnsafe
VIPRETrojan.Win32.Urelas.ab (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.35f1f7
BaiduWin32.Trojan.Urelas.a
VirITTrojan.Win32.AVKill.BWMP
CyrenW32/Coxy.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
ClamAVWin.Trojan.9484703-1
KasperskyVHO:Backdoor.Win32.Plite.gen
BitDefenderGen:Heur.Mint.SP.Urelas.1
AvastWin32:Dropper-NAY [Drp]
TencentTrojan.Win32.Urelas.16000132
SophosML/PE-A + Troj/Urelas-Q
ComodoTrojWare.Win32.Small.NAF@531prv
DrWebTrojan.AVKill.32775
ZillyaTrojan.Urelas.Win32.601
McAfee-GW-EditionBehavesLike.Win32.Corrupt.gc
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.zjx
AviraBDS/Backdoor.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.3505160
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Heur.Mint.SP.Urelas.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Urelas.R77701
McAfeeGenericRXAA-AA!D62447E35F1F
MAXmalware (ai score=88)
VBA32BScope.Trojan.AVKill
MalwarebytesMalware.AI.2051023569
RisingTrojan.Gupboot!1.9CEA (RDMK:cmRtazrsImAi8vlF5LnmfwcyO+X8)
YandexBackdoor.Agent!FfeApb+JcLY
IkarusTrojan-Spy.Cardspy
FortinetW32/Urelas.O!tr
BitDefenderThetaGen:NN.ZexaF.34182.zmXaayXCF1gO
AVGWin32:Dropper-NAY [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VHO:Backdoor.Win32.Plite?

VHO:Backdoor.Win32.Plite removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment