Malware

Win32/Korplug.MO removal instruction

Malware Removal

The Win32/Korplug.MO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Korplug.MO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the PoisonIvy malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Korplug.MO?


File Info:

name: 89D0CDD3617C118C6BA1.mlw
path: /opt/CAPEv2/storage/binaries/c81dd8dd3623181cbc117ca7255e6ea530f770c05624c6896362f03fbfc06280
crc32: 71286E79
md5: 89d0cdd3617c118c6ba1a720e9f9bd62
sha1: b69594d1fc9d44bb89fa09cacfbf61723b7fe1bd
sha256: c81dd8dd3623181cbc117ca7255e6ea530f770c05624c6896362f03fbfc06280
sha512: b9047fd2c3bb4633a3337a173c1d8309eccd2dce01ced8a0f024800b7c3792849b21026decab9beb0ad3e08e97c9e1ac4d820ff6465acef89949793b83514325
ssdeep: 3072:DQIURTXJ+Mu2lvWqB8LjIpKwjeHIw9Taetj:Ds9TlvREYK+eqed
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6A3F11C62C494ABE23707331676ABB9E7B6E3122760051B5B915FFF2826183CD1A2D3
sha3_384: 1e1581c2dd3a5f3e7e6de676eb8b26aa941ca772b064db54a1397d742d2d0bd2dcfcc1d492cc33e08ca3a550c2b73d8f
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Win32/Korplug.MO also known as:

LionicTrojan.Win32.SelfDel.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.40207890
FireEyeTrojan.GenericKD.40207890
McAfeeArtemis!89D0CDD3617C
MalwarebytesTrojan.Happili
SangforTrojan.Win32.Korplug.SB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/SelfDel.0019c1e8
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34182.aq4@a0xFV8g
VirITTrojan.Win32.Genus.BNY
CyrenW32/Gulpix.NNKG-7583
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Korplug.MO
TrendMicro-HouseCallTROJ_FRS.0NA103C320
Paloaltogeneric.ml
ClamAVWin.Trojan.SoftCell-7156347-0
KasperskyTrojan.Win32.SelfDel.gjsp
BitDefenderTrojan.GenericKD.40207890
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywareTrojan.Agent/Gen-Tracur
AvastWin32:Malware-gen
TencentWin32.Trojan.Selfdel.Edxo
Ad-AwareTrojan.GenericKD.40207890
SophosMal/Generic-R
ComodoMalware@#1bx2y2ffcqjb1
F-SecureHeuristic.HEUR/AGEN.1135416
DrWebTrojan.DownLoader26.43168
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103C320
McAfee-GW-EditionBackDoor.gen.b
EmsisoftTrojan.GenericKD.40207890 (B)
APEXMalicious
WebrootW32.Gen.BT
AviraHEUR/AGEN.1112188
Antiy-AVLTrojan/Generic.ASMalwS.258B713
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.GenericKD.40207890
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2490464
VBA32Trojan.Wacatac
ALYacTrojan.Agent.SelfDel
MAXmalware (ai score=100)
CylanceUnsafe
RisingBackdoor.Gulpix!8.3DA (CLOUD)
YandexBackdoor.Gulpix!c7a4HMhDPdc
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.12308541.susgen
FortinetW32/Gulpix.XUE!tr.bdr
AVGWin32:Malware-gen
Cybereasonmalicious.3617c1
PandaTrj/CI.A

How to remove Win32/Korplug.MO?

Win32/Korplug.MO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment