Backdoor

Backdoor.Win32.DarkKomet.iicc removal

Malware Removal

The Backdoor.Win32.DarkKomet.iicc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.DarkKomet.iicc virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

How to determine Backdoor.Win32.DarkKomet.iicc?


File Info:

crc32: 6A609EC8
md5: 68e3236ee4103ea6cba4751b825a3c2e
name: 68E3236EE4103EA6CBA4751B825A3C2E.mlw
sha1: 7f0cb24a9b88e0e7f226c5adebc8185a807524f6
sha256: f696bb0ca1c8c2d9fc4a65cacafd614945e657c262926d34f18dfe4a958ced7d
sha512: 0537e1c7656dca8d408d62711f6ad43fe7ea53d450d1b9149432bc5afc8eff8acc87e5d5c359940dc62236d8e7f1c4653358ba5d39b35c7d9778a815ffe60fb8
ssdeep: 12288:y9HFJ9rJxRX1uVVjoaWSoynxdO1FVBaOiRZTERfIhNkNCCLo9Ek5C/h5:eZ1xuVVjfFoynPaVBUR8f+kN10EB3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.DarkKomet.iicc also known as:

BkavW32.FamVT.DeagezLQ.Trojan
Elasticmalicious (high confidence)
DrWebBackDoor.Tordev.976
ClamAVWin.Trojan.DarkKomet-1
CAT-QuickHealBackdoor.Fynloski.A9
ALYacTrojan.Inject.AUZ
CylanceUnsafe
ZillyaBackdoor.DarkKomet.Win32.30208
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWBackdoor ( 003b505d1 )
K7AntiVirusBackdoor ( 003b505d1 )
BaiduWin32.Backdoor.Agent.l
CyrenW32/Downloader.C.gen!Eldorado
SymantecBackdoor.Graybird
ESET-NOD32Win32/Fynloski.AA
ZonerTrojan.Win32.88734
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.DarkKomet.iicc
BitDefenderTrojan.Inject.AUZ
NANO-AntivirusTrojan.Win32.DarkKomet.ecawjb
ViRobotBackdoor.Win32.Agent.674304.A
MicroWorld-eScanTrojan.Inject.AUZ
TencentBackdoor.Win32.Darkkomet.a
Ad-AwareTrojan.Inject.AUZ
SophosML/PE-A + Troj/Backdr-ID
ComodoBackdoor.Win32.Agent.XAB@4of2bc
F-SecureBackdoor.BDS/DarkKomet.GS
BitDefenderThetaAI:Packer.5A8EF8D41C
VIPRETrojan.Win32.Generic!SB.0
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jh
FireEyeGeneric.mg.68e3236ee4103ea6
EmsisoftTrojan.Fynloski (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.adygq
Webroot
AviraBDS/DarkKomet.GS
eGambitRAT.DarkComet
Antiy-AVLTrojan/Generic.ASBOL.D9B
MicrosoftBackdoor:Win32/Fynloski.PA!MTB
GridinsoftBackdoor.Win32.Fynloski.zv!n
ArcabitTrojan.Inject.AUZ
SUPERAntiSpywareBackdoor.Fynloski/Variant
GDataWin32.Backdoor.DarkComet.H
TACHYONBackdoor/W32.DP-DarkKomet.674304
AhnLab-V3Win-Trojan/Keylogger.679832
Acronissuspicious
McAfeeGeneric BackDoor.xa
MAXmalware (ai score=85)
VBA32Backdoor.DarkKomet
MalwarebytesSpyware.KeyLogger
PandaTrj/Packed.B
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.DarkComet!1.CB87 (CLASSIC)
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
MaxSecureBackdoor.DarkComet
FortinetW32/Generic.AC.25E!tr
AVGMSIL:GenMalicious-CHX [Trj]

How to remove Backdoor.Win32.DarkKomet.iicc?

Backdoor.Win32.DarkKomet.iicc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment