Backdoor

How to remove “Backdoor.DarkComet.UPX”?

Malware Removal

The Backdoor.DarkComet.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.DarkComet.UPX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.DarkComet.UPX?


File Info:

name: F1DA28EFDDFEC5E17295.mlw
path: /opt/CAPEv2/storage/binaries/b3146bdf4b38ca3515ab8685d383708e3afdb9dd8f9e573cd7899ce0e842e83e
crc32: 3D1EFE64
md5: f1da28efddfec5e1729551dea6a4ba3a
sha1: ea4470e1e351c759bdf86c66d149c3405c853d9e
sha256: b3146bdf4b38ca3515ab8685d383708e3afdb9dd8f9e573cd7899ce0e842e83e
sha512: 3da474eaa0a750c6f1bcf5af829f10c7bc1c08c9c1d1fb198b34f08cc8866ecd0d0d6fdc9cb585670dac474755399cac77bd1b6832fb483ec123afddab579fba
ssdeep: 24576:TsqYmIyo7PPm8rHzFvUP62Ox6RTLZSuTNG2Q+qllT5:4qYmIF+sHzFsPVeIJSi1Q9lL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14025237EA1905422E140DDBCACBBE4D04744646C1D6DBA80ABCCEDA7337F1BD52F168A
sha3_384: 8cf469b440ea0b4afdb36f6d2c8b6ada7725f8e4df53830536ff9e9bf7e61eca9557bf872352255c3ad73818c351f12e
ep_bytes: 60be00604f008dbe00b0f0ff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments:
Translation: 0x041f 0x04e6

Backdoor.DarkComet.UPX also known as:

DrWebTrojan.DownLoader22.9658
MicroWorld-eScanDropped:Trojan.GenericKD.37940051
FireEyeDropped:Trojan.GenericKD.37940051
CAT-QuickHealW32.Delf.NB4
ALYacDropped:Trojan.GenericKD.37940051
CylanceUnsafe
ZillyaBackdoor.DarkKomet.Win32.45107
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/DarkKomet.359
K7GWTrojan ( 0056a6201 )
K7AntiVirusTrojan ( 0056a6201 )
BitDefenderThetaAI:Packer.F5AF03D517
CyrenW32/Backdoor.OAZM-5661
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.NBX
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
KasperskyBackdoor.Win32.DarkKomet.hqxy
BitDefenderDropped:Trojan.GenericKD.37940051
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
AvastWin32:Evo-gen [Susp]
TencentVirus.Win32.DarkKomet.a
EmsisoftDropped:Trojan.GenericKD.37940051 (B)
ComodoVirus.Win32.Agent.DE@74b38h
VIPREBehavesLike.Win32.Malware.eah (mx-v)
TrendMicroVirus.Win32.NAPWHICH.B
McAfee-GW-EditionGenericRXRA-IF!60B71D13F594
SophosGeneric ML PUA (PUA)
IkarusJS.Trojan-Downloader.Agent
JiangminWin32/Synaptics.Gen
AviraDR/Delphi.Gen
Antiy-AVLTrojan[Downloader]/Script.AGeneric
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
GDataWin32.Backdoor.Agent.AXS
CynetMalicious (score: 99)
AhnLab-V3Win32/Zorex.X1799
McAfeeArtemis!F1DA28EFDDFE
MAXmalware (ai score=85)
VBA32TScope.Trojan.Delf
MalwarebytesBackdoor.DarkComet.UPX
RisingTrojan.Win32.Lebag.b (CLOUD)
YandexTrojan.GenAsa!ETONJRQzPLk
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.NBX!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.fddfec
PandaTrj/CI.A

How to remove Backdoor.DarkComet.UPX?

Backdoor.DarkComet.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment