Malware

How to remove “Flooder.Win32.CoreWarrior”?

Malware Removal

The Flooder.Win32.CoreWarrior is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Flooder.Win32.CoreWarrior virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Flooder.Win32.CoreWarrior?


File Info:

name: C4C61B79B68BE3D6B2B4.mlw
path: /opt/CAPEv2/storage/binaries/517bcb4cd98296c1d2c034db7ac29cda49b2293b03c8a99207c36884f2193a8b
crc32: 5FBAEF9C
md5: c4c61b79b68be3d6b2b4ef7e2f12ec98
sha1: 7c2b6492ca052459921cecd2388266f3366f7340
sha256: 517bcb4cd98296c1d2c034db7ac29cda49b2293b03c8a99207c36884f2193a8b
sha512: 2d9125c4dd594ec60f11e51c3c33166eb5f6a103d5c250438d5387af446265e9704ad7035ddb366a7b6a300b612fac4d8212878cd3cbeb5f1d32c492fa8fbf8d
ssdeep: 1536:LJaPJpAz869DUxWB+i4OQ4NR2Kk+aSnfZaG8fcaOCzGquSE0cF+sK:LJ0TAz6Mte4A+aaZx8EnCGVus
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F383021646DF58F7E4AB127D469D9063B2FBA06F4BCE3EDBE1FC224DD6162B01580248
sha3_384: 7b53214ae192329d6dcdb2c6f3e04f2e6969380d3aea0ed133d6b1c270810ccacbd05feac95afc5a2081570f912a8bb2
ep_bytes: 60be154041008dbeebcffeff5783cdff
timestamp: 2014-07-01 18:02:13

Version Info:

0: [No Data]

Flooder.Win32.CoreWarrior also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanApplication.Agent.BPO
FireEyeApplication.Agent.BPO
SkyhighBehavesLike.Win32.BadFile.mc
McAfeeArtemis!C4C61B79B68B
MalwarebytesMalware.AI.1754406724
ZillyaTrojan.Agent.Win32.3906285
SangforTrojan.Win32.Agent.V6me
K7AntiVirusTrojan ( 00575d031 )
K7GWTrojan ( 00575d031 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.36802.fmGfaC@Dadi
VirITTrojan.Win32.AgentT.DYK
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent.AAEF
ClamAVWin.Malware.Cymt-10023133-0
KasperskyHEUR:Flooder.Win32.CoreWarrior.gen
BitDefenderApplication.Agent.BPO
NANO-AntivirusTrojan.Win32.Snojan.jqzopm
AvastWin32:Banker-LAA [Trj]
RisingDownloader.Snojan!8.ECDD (TFE:5:V47YrAkOYKG)
EmsisoftApplication.Agent.BPO (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen2
DrWebTool.Snojan.1
VIPREApplication.Agent.BPO
Trapminesuspicious.low.ml.score
SophosTroj/Bdoor-BHD
SentinelOneStatic AI – Suspicious PE
JiangminDownloader.Snojan.adp
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
VaristW32/Agent.FBOO-5422
Antiy-AVLTrojan/Win32.Phonzy
MicrosoftTrojanDownloader:Win32/Nemucod
XcitiumTrojWare.Win32.Snojan.B@7h1cjp
ArcabitApplication.Agent.BPO
ZoneAlarmHEUR:Flooder.Win32.CoreWarrior.gen
GDataWin32.Application.Snojan.A
CynetMalicious (score: 100)
Acronissuspicious
VBA32Flooder.CoreWarrior
ALYacApplication.Agent.BPO
MAXmalware (ai score=74)
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.GenKryptik.kac
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.159307391.susgen
FortinetRiskware/Snojan
AVGWin32:Banker-LAA [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Nemucod

How to remove Flooder.Win32.CoreWarrior?

Flooder.Win32.CoreWarrior removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment