Backdoor

Backdoor.Win32.DarkKomet.bvlo (file analysis)

Malware Removal

The Backdoor.Win32.DarkKomet.bvlo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.DarkKomet.bvlo virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Anomalous binary characteristics

How to determine Backdoor.Win32.DarkKomet.bvlo?


File Info:

crc32: 9651CB5B
md5: 3a80887987941f27bd0a95a65eaff45d
name: 3A80887987941F27BD0A95A65EAFF45D.mlw
sha1: 3f87de9a59847cb787a0a0789ae05332df346330
sha256: 3974e48e2940936436260bc98dc5faab3787a0d97d39fb753eeb3d25fb2073ab
sha512: ee4db2fdf5d7a2d8c4a1c978684370c7a1d579ead1424b0b9ab6308a8605f84dd9a76d55cf2a628f3f186a3c9c398f53cd7c4f0964ce08ad7389bfd07ff2df31
ssdeep: 6144:p6LwFnQ+VoVJYCsy7cSuvqEsbH8OnMlzpDCJJTRlmYDsm:IadWxxEAc+ysJJNlrX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
InternalName: stub
FileVersion: 860.655.4356
CompanyName: Ro
ProductName: rerererr
ProductVersion: 860.655.4356
OriginalFilename: stub.exe

Backdoor.Win32.DarkKomet.bvlo also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBInject.WR3
ALYacGen:Variant.Bulz.115316
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/DarkKomet.9777c7d4
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.987941
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BEOO
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.DarkKomet.bvlo
BitDefenderGen:Variant.Bulz.115316
NANO-AntivirusTrojan.Win32.DarkKomet.feprdp
MicroWorld-eScanGen:Variant.Bulz.115316
Ad-AwareGen:Variant.Bulz.115316
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34628.ym3@aSrYHmL
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.3a80887987941f27
EmsisoftGen:Variant.Bulz.115316 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/DarkKomet.exe
AviraTR/Dropper.Gen
MicrosoftPWS:Win32/Zbot.GG!MTB
GDataGen:Variant.Bulz.115316
AhnLab-V3Trojan/Win32.Zbot.R102020
McAfeeGenericRXGE-UR!3A8088798794
MAXmalware (ai score=87)
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.2325130949
PandaTrj/Genetic.gen
RisingMalware.Zbot!8.E95E (CLOUD)
YandexTrojan.GenAsa!DWZoLwqCXv4
IkarusTrojan-Dropper.Win32.Injector
FortinetW32/Filecoder_CTBLocker.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Zbot.HwMA5x8A

How to remove Backdoor.Win32.DarkKomet.bvlo?

Backdoor.Win32.DarkKomet.bvlo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment