Backdoor

MemScan:Backdoor.DarkKomet.F (file analysis)

Malware Removal

The MemScan:Backdoor.DarkKomet.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Backdoor.DarkKomet.F virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
Tubexe-23569.portmap.host

How to determine MemScan:Backdoor.DarkKomet.F?


File Info:

crc32: 9EE8CD21
md5: 8d949fe494a783d96dc2bd003de89a41
name: 8D949FE494A783D96DC2BD003DE89A41.mlw
sha1: f694ad1cb07a98e3ede5dcd26d54f1e4d29dc3b8
sha256: 27db51f010cd9e7f83daf474ba1d78022cf61704fe114552a98d464b08383b38
sha512: c23dc841784b4febfbcc42ee69d18ef0f77bed3ccd779faa606113d2a5b4eb030b646aeeffb8bf6c277d29a56cd18d08fa768fe442a59518a9710b7a31f9544c
ssdeep: 196608:b7P/9NcSdKX8VEwb3y+9Is3/K2CBHpR1FtSeFo38U9cJ81+:XP/9GnerKQCHzCb+P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Backdoor.DarkKomet.F also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanMemScan:Backdoor.DarkKomet.F
CAT-QuickHealVirtool.Vbinder.A4
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen
McAfeeGenericRXEL-MH!8D949FE494A7
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0040f2c01 )
BitDefenderMemScan:Backdoor.DarkKomet.F
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.494a78
TrendMicroTROJ_VBINDER.SM
CyrenW32/GenTroj.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyBackdoor.Win32.Poison.ggrf
NANO-AntivirusTrojan.Win32.Poison.cbeljp
ViRobotBackdoor.Win32.Agent.67584.L
TencentMalware.Win32.Gencirc.10b3e7f9
Ad-AwareMemScan:Backdoor.DarkKomet.F
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop8.22787
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.8d949fe494a783d9
EmsisoftMemScan:Backdoor.DarkKomet.F (B)
IkarusVirus.Win32.Vbinder
JiangminBackdoor/Poison.abtg
WebrootW32.Dropper.Gen
AviraTR/Dropper.Gen
MicrosoftVirTool:Win32/CeeInject.WI!bit
ArcabitBackdoor.DarkKomet.F
ZoneAlarmBackdoor.Win32.Poison.ggrf
GDataWin32.Trojan-Dropper.Agent.AMY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fynloski.R43608
Acronissuspicious
BitDefenderThetaAI:Packer.B9B0641A20
ALYacMemScan:Backdoor.DarkKomet.F
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Poison
MalwarebytesBackdoor.Dropper
PandaTrj/Injector.BH
ESET-NOD32a variant of Win32/TrojanDropper.Small.NMM
TrendMicro-HouseCallTROJ_VBINDER.SM
RisingDropper.Win32.Small.bnv (CLASSIC)
YandexTrojan.GenAsa!T8P/UkYT/k8
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Xorist.ET!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove MemScan:Backdoor.DarkKomet.F?

MemScan:Backdoor.DarkKomet.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment