Backdoor

Backdoor:Win32/Knockex.H (file analysis)

Malware Removal

The Backdoor:Win32/Knockex.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Knockex.H virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Knockex.H?


File Info:

name: 255DEDB179602B2B50BD.mlw
path: /opt/CAPEv2/storage/binaries/b298e7a6a79a34b10e3bcf4800002fbb30572c1573e9f72f5978956b1fab9172
crc32: E6B5CBEA
md5: 255dedb179602b2b50bdee6f9fa8c7ca
sha1: 175736bbec01154b62f05e67f0c0a549308a499e
sha256: b298e7a6a79a34b10e3bcf4800002fbb30572c1573e9f72f5978956b1fab9172
sha512: 21ea724380fac861ebdaa2b796f75de692b92b2a2616303e48e5b70f789e7debef5db9de8e2624c28018e80658b8e943464b69cbbb5f7ce1dd9258735005fae0
ssdeep: 768:LsckR3boVuwz8lnLGToPKsRDP59k1BSfkcd5e3DG3pLRmKzuexlap+f+:8tXwz8NqElRDP5EB0kcdWDGZFdNxl+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C23F1353243E730E98B19B7FB7781DA17611DE2287223D6869FE0EE12DF1616A0D934
sha3_384: b870c65710a33644ec2b544900477870445cd0a7abb1f06d82950415978348da1d634fbe165fe69c74ed32d48d91e5a8
ep_bytes: 8d3dfc83400066c1ef1381c7fc8b0000
timestamp: 2008-04-27 09:09:42

Version Info:

0: [No Data]

Backdoor:Win32/Knockex.H also known as:

BkavW32.Common.00B00AE8
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader.63788
MicroWorld-eScanTrojan.Packed.Gen.1
FireEyeGeneric.mg.255dedb179602b2b
McAfeeArtemis!255DEDB17960
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.21720
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
AlibabaMalware:Win32/km_28310.None
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.179602
BitDefenderThetaAI:Packer.517E01321D
VirITBackdoor.Agent.BI
CyrenW32/Backdoor.RVMA-4926
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.PBE
APEXMalicious
TrendMicro-HouseCallBKDR_AGENT.ABYT
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-64291
KasperskyBackdoor.Win32.Dreamy.gfe
BitDefenderTrojan.Packed.Gen.1
NANO-AntivirusTrojan.Win32.Zhelatin.cwgafe
TencentWin32.Backdoor.Dreamy.Hpsf
Ad-AwareTrojan.Packed.Gen.1
EmsisoftTrojan.Packed.Gen.1 (B)
ComodoBackdoor@#1q7rmcqvga3om
VIPRETrojan.Packed.Gen.1
TrendMicroBKDR_AGENT.ABYT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.pc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-CG
SentinelOneStatic AI – Malicious PE
GDataTrojan.Packed.Gen.1
JiangminBackdoor/Agent.aucs
WebrootW32.Trojan.Storm.Gen
GoogleDetected
AviraWORM/Zhelatin.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Hack.Dreamy.e.(kcloud)
ArcabitTrojan.Packed.Gen.1
ViRobotBackdoor.Win32.Agent.46080
MicrosoftBackdoor:Win32/Knockex.H
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Backdoor.Agent
ALYacTrojan.Packed.Gen.1
MalwarebytesMalware.AI.2790084077
PandaTrj/Genetic.gen
RisingMalware.Zbot!8.E95E (TFE:5:RC8VHK0TJCE)
YandexTrojan.GenAsa!j/6DVyYJtnc
IkarusBackdoor.Win32.Dreamy
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PKN.DA!tr
AVGWin32:Tibser [Trj]
AvastWin32:Tibser [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Knockex.H?

Backdoor:Win32/Knockex.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment