Backdoor

Backdoor:Win32/Fynloski.K removal instruction

Malware Removal

The Backdoor:Win32/Fynloski.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Fynloski.K virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Sniffs keystrokes
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Fynloski.K?


File Info:

crc32: F96DE27B
md5: a107d7009c970e35fd2c99f1cf3b6b6b
name: 23532141.exe
sha1: ddf81db6e588c07f182b85d7b24e423f7f02f0a1
sha256: 154cf0296a398c8cbf1c23405e38f75718cb98f4d1a2ee86936ca37e97c6a197
sha512: 3997c25a7e5621f7d954f31a7e32b0b288121e29482d263b69444998c729551f935eb2827bb19b1196a38390c2938c5b9370f3b4888433243f31bc687fec72d0
ssdeep: 6144:VcNYS996KFifeVjBpeExgVTFSXFoMc5RhCaL37:VcW7KEZlPzCy37
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Fynloski.K also known as:

BkavW32.LebomeP.Trojan
K7AntiVirusBackdoor ( 003b505d1 )
MicroWorld-eScanTrojan.Inject.AUZ
CMCBackdoor.Win32.DarkKomet!O
CAT-QuickHealBackdoor.Fynloski.A9
ALYacTrojan.Inject.AUZ
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
K7GWBackdoor ( 003b505d1 )
CrowdStrikemalicious_confidence_100% (W)
ArcabitTrojan.Inject.AUZ
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
CyrenW32/Downloader.C.gen!Eldorado
SymantecBackdoor.Graybird
TotalDefenseWin32/Fynloski.DY
TrendMicro-HouseCallBKDR_FYNLOS.SMM
Paloaltogeneric.ml
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Backdoor.Fynloski.F
KasperskyBackdoor.Win32.DarkKomet.aagt
BitDefenderTrojan.Inject.AUZ
NANO-AntivirusTrojan.Win32.DarkKomet.dtlfre
ViRobotBackdoor.Win32.Agent.674304.A[UPX]
SUPERAntiSpywareTrojan.Agent/Gen-Fynloski
RisingBackdoor.Pontoeb!1.6637 (CLASSIC)
Ad-AwareTrojan.Inject.AUZ
EmsisoftTrojan.Inject.AUZ (B)
F-SecureTrojan.Inject.AUZ
DrWebBackDoor.Tordev.976
ZillyaBackdoor.DarkKomet.Win32.30287
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
SophosTroj/Backdr-ID
SentinelOnestatic engine – malicious
F-ProtW32/Downloader.C.gen!Eldorado
JiangminTrojan/Genome.bomw
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
Endgamemalicious (moderate confidence)
AegisLabBackdoor.W32.DarkKomet.mzOX
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Fynloski.K
AhnLab-V3Win-Trojan/FCN.140610
McAfeeGeneric.gj
AVwareBackdoor.Win32.Fynloski.A (v)
MAXmalware (ai score=99)
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Fynloski.AM
ESET-NOD32a variant of Win32/Fynloski.AN
TencentBackdoor.Win32.Darkkomet.a
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
eGambitTrojan.Generic
FortinetW32/Generic.AC.25E!tr
AVGWin32:Agent-AWZS [Trj]
AvastWin32:Agent-AWZS [Trj]
Qihoo-360Win32/Backdoor.Bot.D

How to remove Backdoor:Win32/Fynloski.K?

Backdoor:Win32/Fynloski.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment