Trojan

How to remove “Trojan.BlockerRI.S17616033”?

Malware Removal

The Trojan.BlockerRI.S17616033 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.BlockerRI.S17616033 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

How to determine Trojan.BlockerRI.S17616033?


File Info:

crc32: 6BA85FE6
md5: 806b65a2f241146d01b77369371e59f6
name: 806B65A2F241146D01B77369371E59F6.mlw
sha1: f95281954408ad3132235c0baa6f75ae00cd748a
sha256: 5daf38ba7d08872375f14a3d8de794d20aa37e1caeda4da0558e2a9cd4ed668a
sha512: 5c0152ae672a9557244d960c8838e36e0ccdad7234df1076a621f07d4cea5348d6d982fe41dd1060503baa0d69969913d82119b15e8c89f6641b55d806a7946f
ssdeep: 12288:Z9HFJ9rJxRX1uVVjoaWSoynxdO1FVBaOiRZTERfIhNkNCCLo9Ek5C/hR3:jZ1xuVVjfFoynPaVBUR8f+kN10EBb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 2012
InternalName: BindStub
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: BindStub
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: BindStub
OriginalFilename: BindStub.exe
Translation: 0x0409 0x04b0

Trojan.BlockerRI.S17616033 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Comet.152
ClamAVWin.Trojan.DarkKomet-1
CAT-QuickHealTrojan.BlockerRI.S17616033
ALYacBackdoor.Generic.755288
CylanceUnsafe
ZillyaBackdoor.DarkKomet.Win32.4059
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004020ef1 )
K7AntiVirusTrojan ( 004020ef1 )
BaiduWin32.Trojan-Dropper.Agent.ca
CyrenW32/Agent.NXNL-3094
SymantecBackdoor.Breut!gm
ESET-NOD32Win32/TrojanDropper.Agent.PYN
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.hrft
BitDefenderBackdoor.Generic.755288
NANO-AntivirusTrojan.Win32.DarkKomet.ecawjb
MicroWorld-eScanBackdoor.Generic.755288
TencentTrojan-Ransom.Win32.Blocker.a
Ad-AwareBackdoor.Generic.755288
SophosML/PE-A + Troj/Backdr-ID
ComodoTrojWare.Win32.Agent.pyn@54cqtm
F-SecureBackdoor.BDS/DarkKomet.GS
BitDefenderThetaAI:Packer.63D972051C
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionGenericRXCZ-BR!806B65A2F241
FireEyeGeneric.mg.806b65a2f241146d
EmsisoftBackdoor.Generic.755288 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/DarkKomet.kwk
AviraBDS/DarkKomet.GS
eGambitRAT.DarkComet
Antiy-AVLTrojan/Generic.ASBOL.D9B
KingsoftHeur.SSC.2700553.0111.(kcloud)
MicrosoftTrojanDropper:Win32/Effbee.A
GridinsoftBackdoor.Win32.DarkKomet.vl!n
ArcabitBackdoor.Generic.DB8658
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
ZoneAlarmTrojan-Ransom.Win32.Blocker.hrft
GDataWin32.Trojan-Dropper.BeiF.A
AhnLab-V3Backdoor/Win32.DarkKomet.R48242
McAfeeGenericRXCZ-BR!806B65A2F241
MAXmalware (ai score=82)
VBA32Hoax.Blocker
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.DarkComet!1.CB87 (CLASSIC)
YandexTrojan.GenAsa!N71EllaXIy8
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Dropper.PYN!tr
AVGMSIL:GenMalicious-CHX [Trj]

How to remove Trojan.BlockerRI.S17616033?

Trojan.BlockerRI.S17616033 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment