Adware

Win32/Adware.RK.AB malicious file

Malware Removal

The Win32/Adware.RK.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.RK.AB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.RK.AB?


File Info:

name: 25FA2CCF4494F640BE9A.mlw
path: /opt/CAPEv2/storage/binaries/d6ddc02cdf052e10e796186cce7135e085d6d94ed60c0e6503b6226a181015ea
crc32: D93E4141
md5: 25fa2ccf4494f640be9a833660efcfdb
sha1: 7a2564d184ceef11f95af9dc4d4f90a2f19cab26
sha256: d6ddc02cdf052e10e796186cce7135e085d6d94ed60c0e6503b6226a181015ea
sha512: 44a28aeddeb5ebd90add86fc4222645d07a647fa07ce7beb9f782d618d25683acbd0ea042e49f862dbe26f3eea04f4b881feea88c235e9d2fec5b9807e48d59e
ssdeep: 12288:mM6XFpLh1Pr9hOR9QcIxX/fqc7gvKrsoyM9dL:mhXzTD9hORn6/uvyy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BB46C03B3C0A536C5A302315A4F6776B7B9BD746A726403B74C361C6FB1991A233BCA
sha3_384: e334d32dab24158edad2a1d8a5fb413c8b4b86ce685329851ce99ccc0fac3a856409d9e6db52c763e691426404382b6d
ep_bytes: 6a6068808c4400e8202b0000bf940000
timestamp: 2009-06-10 21:30:38

Version Info:

CompanyName: TMRG, INC.
FileDescription: RelevantKnowledge Installer
FileVersion: 1, 0, 0, 82
InternalName: RKInstaller.exe
LegalCopyright: Copyright (C) 2005-2009
OriginalFilename: RKInstaller.exe
ProductVersion: 1, 0, 0, 82
Translation: 0x0409 0x04b0

Win32/Adware.RK.AB also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.RK.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Relevant.BA
FireEyeGeneric.mg.25fa2ccf4494f640
McAfeeArtemis!25FA2CCF4494
CylanceUnsafe
ZillyaAdware.RK.Win32.2065
SangforTrojan.Win32.RK.gen
K7AntiVirusAdware ( 00586ae21 )
AlibabaRiskWare:Win32/Relevant.9ce2e190
K7GWAdware ( 00586ae21 )
Cybereasonmalicious.f4494f
CyrenW32/AdSpy.KYIX-4007
ESET-NOD32Win32/Adware.RK.AB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Adware.Relevant-2
Kasperskynot-a-virus:HEUR:Monitor.Win32.RK.gen
BitDefenderAdware.Relevant.BA
NANO-AntivirusTrojan.Win32.Relevant.xrotp
SUPERAntiSpywareSpyware.RelevantKnowledge
AvastWin32:Adware-gen [Adw]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareAdware.Relevant.BA
EmsisoftAdware.Relevant.BA (B)
ComodoMalware@#3mk8c5m8mtuzj
DrWebAdware.Relevant.79
VIPREAdware.Win32.RelevantKnowledge.a (v)
TrendMicroTROJ_GEN.R002C0WIO21
McAfee-GW-EditionArtemis
SophosRKnowledge Installer (PUA)
IkarusAdWare.Relevant
GDataAdware.Relevant.BA
JiangminAdware/Relevant.c
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1106744
Antiy-AVLTrojan/Generic.ASMalwS.48B2A
ArcabitAdware.Relevant.BA
CynetMalicious (score: 100)
VBA32Adware.Relevant.0961
MAXmalware (ai score=99)
MalwarebytesPUP.Optional.RelevantKnowledge
TrendMicro-HouseCallTROJ_GEN.R002C0WIO21
RisingAdware.PremierOpinion!1.BB5B (CLASSIC)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_71%
FortinetRiskware/OSS
AVGWin32:Adware-gen [Adw]
MaxSecureTrojan.Malware.2782760.susgen

How to remove Win32/Adware.RK.AB?

Win32/Adware.RK.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment