| Detection Names : | Spyware.14597 Dropped:Spyware.14597 Trojan-Dropper:W32/Knockex.A Trojan-Downloader:W32/Knockex.A Gen:Variant.Kazy.17250 Backdoor:W32/Knockex.A Trojan.Generic.KDV.171682 Rootkit:W32/Knockex.A Trojan.Downloader.Agent.ZBU Spyware:W32/Inet.B Adware:W32/MyWebSearch.AG Adware:W32/MyWebSearch.AF Adware:W32/MyWebSearch.AH Spyware:W32/Inet.A Adware:W32/Zwangi.O |
| Category: | Malware |
| Type: | Backdoor |
| Platform: | W32 |
To remove the backdoor program and other malwares, allow F-Secure Anti-Virus to disinfect the relevant files.
For more general information on disinfection, please see Removal Instructions.
To remove the installed adwares, uninstall the following programs from the Windows 'Add/Remove Programs' menu:
Backdoor:W32/Knockex.A is a backdoor program dropped as part of the payload of a Nullsoft installer (NSIS) program detected as Trojan-Dropper:W32/Knockex.A.
The Nullsoft installer contains the following sub-installers:
These installers will themselves install multiple installers, which in turn install malware, adware and spyware programs. Among the installed programs is Backdoor:w32/Knockex.A.
First Installer Dropped - OfferApp-2529.exe
As of this writing, the first installer dropped by Trojan-Dropper:W32/Knockex.A, OfferApp-2529.exe, downloads and executes a backdoor with rootkit capabilities. The backdoor is detected either as Backdoor:W32/Knockex.A or Trojan.Generic.KDV.171682.
Upon execution, the backdoor program drops the following files:
The backdoor program uses the following launch points:
At the same time the OfferApp-2529.exe file is downloading and executing the backdoor, the second installer file, OfferApp-2526.exe, is executing the following installers:
When the installers listed are executed, their payloads are installed as separate, independent programs.
The myclearsearch-setup.exe file then creates the following service launch point:
And also creates the following registry keys:
During installation, the program will also modify the start page for the Internet Explorer web browser:
When OfferApp-2526.exe is executed, it instructs the inet.exe file installer to download a file from a remote site and install it to the path "C:\Program". During this process, the installer creates the following service launch point:
It will also create a (functional) uninstallation setting:
Brand.exe is an installer that downloads its own components from a remote site. At the time of writing, the file downloads the following components:
It creates the following service launch point:
And also creates the following registry keys: