Home Malware Programs Backdoors BKDR_PLUGX.DMI

BKDR_PLUGX.DMI

Posted: April 26, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 7
First Seen: April 26, 2013
Last Seen: December 11, 2021
OS(es) Affected: Windows

BKDR_PLUGX.DMI is a backdoor Trojan that affects legitimate applications including Microsoft, Lenovo, and McAfee. BKDR_PLUGX.DMI uses normal applications to load its malicious .DLL components on the infected computer system. This .DLL hijacking technique is not new and was initially discussed by last July 2010 by Mandiant here. BKDR_PLUGX.DMI is able to use any executable file and known applications. BKDR_PLUGX.DMI also uses a certain vulnerability found in an executable when .DLLs are loaded, particularly on how executable files load the first .DLL file in a certain folder. BKDR_PLUGX.DMI uses a variety of normal files to load its malicious components on the affected PC. BKDR_PLUGX.DMI uses 'HHC.EXE, which is a legitimate Microsoft file for HTML Help. BKDR_PLUGX.DMI loads 'hha.dll', which then loads 'hha.dll.bak'. Both files are detected as BKDR_PLUGX.DMI.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



HHC.EXE File name: HHC.EXE
File type: Executable File
Mime Type: unknown/EXE
Group: Malware file
hha.dll File name: hha.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
hha.dll.bak File name: hha.dll.bak
Mime Type: unknown/bak
Group: Malware file

Additional Information

The following URL's were detected:
renewappwno1.store
Loading...