Backdoor

What is “BScope.Backdoor.DarkKomet”?

Malware Removal

The BScope.Backdoor.DarkKomet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.DarkKomet virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
xred.mooo.com
freedns.afraid.org
a.tomx.xyz

How to determine BScope.Backdoor.DarkKomet?


File Info:

crc32: AFB3A645
md5: d6347de1a4f3603ce1ed34237ecd344b
name: ksd.exe
sha1: 244957fd2b829f877620600c00df781314e6a48f
sha256: ba7cc750355a3e0fc59dd67f1dd94a74bc1fc30c1af5a76601070412ec701a24
sha512: 4af73dca995c5adbe873e3d41b178e4da89471dc28952a4ef23b62e163a81807d95403a0e4e91597c524562ec6634c2ecba6d2ed3222524dfc4ebb35f54b3727
ssdeep: 49152:KnsHyjtk2MYC5GDAg/Gj4a0zjKdLuyrh6ElG4zovyKa2t:Knsmtk2a6GUaM0Luyrh1lG4zo6p0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.Backdoor.DarkKomet also known as:

MicroWorld-eScanDropped:Trojan.GenericKD.32840913
FireEyeGeneric.mg.d6347de1a4f3603c
CAT-QuickHealW32.Delf.NB4
Qihoo-360Win32/Virus.Synaptics.A
McAfeeGenericRXJO-YL!D6347DE1A4F3
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Trojan.GenericKD.32840913
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1a4f36
TrendMicroVirus.Win32.NAPWHICH.B
F-ProtW32/Zorex.A
APEXMalicious
ClamAVWin.Malware.Delf-6899401-0
GDataDropped:Trojan.GenericKD.32840913
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaTrojanSpy:Win32/Estoler.181228
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
AvastWin32:Zorex-E [Wrm]
TencentMalware.Win32.Gencirc.10b8ace3
Ad-AwareDropped:Trojan.GenericKD.32840913
SophosGeneric PUA LF (PUA)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
DrWebTrojan.DownLoader22.9658
ZillyaTrojan.Delf.Win32.76144
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
Trapminesuspicious.low.ml.score
EmsisoftDropped:Trojan.GenericKD.32840913 (B)
IkarusVirus.Win32.Delf
CyrenW32/Backdoor.OAZM-5661
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
MicrosoftWorm:Win32/AutoRun.XXY!bit
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiCO.34090.IIW@ayBjBviG
ALYacDropped:Trojan.GenericKD.32840913
VBA32BScope.Backdoor.DarkKomet
MalwarebytesTrojan.Agent
ESET-NOD32Win32/Delf.NBX
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpRLtE2xFXPTiXZNJDXLG6O)
YandexBackDoor.Optix!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.NBX!tr
AVGOther:Malware-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove BScope.Backdoor.DarkKomet?

BScope.Backdoor.DarkKomet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment