Backdoor

What is “Backdoor.Win32.Poison.knbo”?

Malware Removal

The Backdoor.Win32.Poison.knbo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Poison.knbo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Win32.Poison.knbo?


File Info:

name: 7EA99992B239840D92A9.mlw
path: /opt/CAPEv2/storage/binaries/a3499d31238223c1e78430eecfede644c162277ae858a4e444bd3f584fbe0d36
crc32: E763604A
md5: 7ea99992b239840d92a92cb818ba04a0
sha1: 11e470906b17660daf638252b448dec340229090
sha256: a3499d31238223c1e78430eecfede644c162277ae858a4e444bd3f584fbe0d36
sha512: 65f3705948e1c26ad7d2f5180089015e5342730e7bb5c6a3aaad9fc0d98689032c449edbf9c13237bb11799651da13cb05cfb5edd1470a7c23cc4b296d27935f
ssdeep: 196608:1MOgfY6lWRXohzhmPEaSPzDkk9hAOwU2BrF6xU9hp7+wc9J6DUd/+x01HUj0UXEe:qTw6oXo/UEaeDrhJLVOf79gADUd/+xok
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104C612FAE41C4264FE4512F5A8B13DFE5E627F216B8434CA90916537FACE8F9660780C
sha3_384: b0b6866ebfcbf0b00cac565e166785e9beba1e84e7cec80d2ed533c7dfe7e9d44dedafee00666789a5453519dccd5a65
ep_bytes: b88c4bc3005064ff3500000000648925
timestamp: 2023-07-17 12:01:24

Version Info:

0: [No Data]

Backdoor.Win32.Poison.knbo also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.7ea99992b239840d
MalwarebytesMalware.Heuristic.1001
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWUnwanted-Program ( 0056626f1 )
K7AntiVirusUnwanted-Program ( 0056626f1 )
BitDefenderThetaGen:NN.ZexaF.36662.@lZfaePh1mpb
CyrenW32/FlyStudio.BC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H07HQ23
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Poison.knbo
AvastWin32:MiscX-gen [PUP]
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1338690
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1M5WJ7V
AviraHEUR/AGEN.1338690
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ZoneAlarmBackdoor.Win32.Poison.knbo
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R598163
Cylanceunsafe
RisingBackdoor.Poison!8.2D7 (CLOUD)
FortinetPossibleThreat.DU
AVGWin32:MiscX-gen [PUP]
Cybereasonmalicious.06b176
DeepInstinctMALICIOUS

How to remove Backdoor.Win32.Poison.knbo?

Backdoor.Win32.Poison.knbo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment