Trojan

MemScan:Trojan.Generic.KDV.584379 removal instruction

Malware Removal

The MemScan:Trojan.Generic.KDV.584379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Generic.KDV.584379 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics
  • Contains RAT configuration for DarkComet (see Static Analysis tab)
  • Uses suspicious command line tools or Windows utilities

Related domains:

laylaylom15975300.freeddns.org
smtp.yandex.com

How to determine MemScan:Trojan.Generic.KDV.584379?


File Info:

crc32: 84C5B5E8
md5: 50889863763dec84072482d72d257a5a
name: 50889863763DEC84072482D72D257A5A.mlw
sha1: ee585ed89df214b743ceb8fe2cf85999e6013806
sha256: cfa850db87d98eed49dec543a7977ef9221dc62bd48c7aaaaafe1327c864aa72
sha512: 4fb2c1a727d4b703e0e88eef85b4d57f181f9a0658219e493f3a3435c98defb0dc845c3d07b5be1d0bac5357f3e2a5b03e38b696fa846e8e17b4fc50f5c5d5eb
ssdeep: 24576:qT0QRWoJEfg0oChGdJQbjPbNW5tYeP+GFpgjMAgjMkV8gjU:qgQRV2o3MPY5AFjM5jMCtjU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Trojan.Generic.KDV.584379 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.39589
ClamAVWin.Trojan.DarkKomet-1
CAT-QuickHealVirTool.Vbinder.CO5
ALYacMemScan:Trojan.Generic.KDV.584379
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0055e3df1 )
K7AntiVirusTrojan ( 0055e3df1 )
BaiduWin32.Trojan-Dropper.Binder.m
CyrenW32/Backdoor.FVDJ-1096
ESET-NOD32Win32/TrojanDropper.Binder.NBH
APEXMalicious
AvastWin32:Delf-SQI [Trj]
CynetMalicious (score: 100)
KasperskyHackTool.Win32.Binder.bs
BitDefenderMemScan:Trojan.Generic.KDV.584379
NANO-AntivirusTrojan.Win32.VB.fahpau
ViRobotTrojan.Win32.A.Swisyn.49120
MicroWorld-eScanMemScan:Trojan.Generic.KDV.584379
TencentMalware.Win32.Gencirc.10b0a728
Ad-AwareMemScan:Trojan.Generic.KDV.584379
SophosMal/Vbinder-D
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
BitDefenderThetaAI:Packer.2EA51FBF1F
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.th
FireEyeGeneric.mg.50889863763dec84
EmsisoftMemScan:Trojan.Generic.KDV.584379 (B)
SentinelOneStatic AI – Malicious PE
JiangminHackTool.Binder.bh
AviraTR/AD.Fynloski.dkaaw
eGambitRAT.DarkComet
Antiy-AVLTrojan/Generic.ASMalwS.14ABB
KingsoftHeur.SSC.3072.1216.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.A
GridinsoftTrojan.Win32.Injector.sb!s1
ArcabitTrojan.Generic.KDV.D8EABB
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
McAfeeTrojan-FDDZ!50889863763D
MAXmalware (ai score=82)
VBA32Binder.Celesty
MalwarebytesDarkComet.Backdoor.RAT.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusBackdoor.Win32.Fynloski
MaxSecureHackTool.W32.Binder.bs
FortinetW32/CoinMiner.NBH!tr
AVGWin32:Delf-SQI [Trj]

How to remove MemScan:Trojan.Generic.KDV.584379?

MemScan:Trojan.Generic.KDV.584379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment