Backdoor

Backdoor.DarkKomet (A) removal

Malware Removal

The Backdoor.DarkKomet (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.DarkKomet (A) virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.DarkKomet (A)?


File Info:

crc32: 3B41B0DB
md5: 04df1aa999711fa1733dc51a6dad84b7
name: 1443fe344fb01883.exe
sha1: 118758acf9a98dda1810234643b5d7b7fd273366
sha256: 37c622306e52563c612aa4a94649c8b18e743481b686565761b891de472260eb
sha512: 7e75e6c8b8fc18c680cb816ffd2f6678700309f91eb81cfe7579b8f53e2dbfd89803a71a3f99121261b4656cba11a78b85d567a8c9a820ce0d86081e1fc08232
ssdeep: 6144:6cNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQJ:6cWkbgTYWnYnt/IDYhPC
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Backdoor.DarkKomet (A) also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.Heur.pmKfr8UVH@iS
CMCBackdoor.Win32.DarkKomet!O
CAT-QuickHealBackdoor.Fynloski.A9
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.pmKfr8UVH@iS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.999711
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.2698ba3d
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
AegisLabTrojan.Win32.DarkKomet.mzOX
RisingBackdoor.Darkcomet!8.1117F (CLOUD)
Ad-AwareGen:Trojan.Heur.pmKfr8UVH@iS
EmsisoftBackdoor.DarkKomet (A)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.04df1aa999711fa1
SophosTroj/Fynlosk-AK
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Endgamemalicious (moderate confidence)
ArcabitTrojan.Heur.E42D2B
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
McAfeeGeneric.gj
TACHYONBackdoor/W32.DP-DarkKomet.674304.B
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
BitDefenderThetaAI:Packer.EBAEB60B1C
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.DarkKomet.B

How to remove Backdoor.DarkKomet (A)?

Backdoor.DarkKomet (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment