Trojan

Trojan.Heur.pmKfrqIFWFiS removal instruction

Malware Removal

The Trojan.Heur.pmKfrqIFWFiS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.pmKfrqIFWFiS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.pmKfrqIFWFiS?


File Info:

crc32: F248B019
md5: e7d173137b2d8f87e543d513d764bc8b
name: 123.exe
sha1: 45d96a9c277542345f44ee93d2340c7408ff6fb2
sha256: 07073fb10a94fc4b56c2de391a5aa010b135240930f3edb93989974662ff3e8b
sha512: 10793ea82fab54aba88cfaaa6041f15650a0bbd08583530afd2236e229a7c9a925da253ad1472b4a157fd16f20585257bb5bb6db3845311073eea86818b226f3
ssdeep: 6144:ccNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQ0:ccWkbgTYWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.pmKfrqIFWFiS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.Heur.pmKfrqIFWFiS
CMCBackdoor.Win32.DarkKomet!O
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
ZillyaTrojan.Fynloski.Win32.742
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.pmKfrqIFWFiS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.37b2d8
ArcabitTrojan.Heur.pmKfrqIFWFiS
Invinceaheuristic
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazodYDiCHrZbQmdrmmuxmhMn)
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Heur.pmKfrqIFWFiS (B)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
MaxSecureBackdoor.W32.DarkKomet.aagr
VIPREBackdoor.Win32.Fynloski.A (v)
TrendMicroBKDR_FYNLOS.SMM
FortinetW32/Generic.AC.DB56!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e7d173137b2d8f87
SophosTroj/Fynlosk-AK
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=82)
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32Backdoor.Tordev
TACHYONBackdoor/W32.DP-DarkKomet.674304.B
Ad-AwareGen:Trojan.Heur.pmKfrqIFWFiS
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
GDataWin32.Trojan-Spy.DarkComet.J
BitDefenderThetaAI:Packer.223EE8B81C
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.C2F8.Malware.Gen

How to remove Trojan.Heur.pmKfrqIFWFiS?

Trojan.Heur.pmKfrqIFWFiS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment