Trojan

Trojan.Heur.pmKfrWHPKZoS malicious file

Malware Removal

The Trojan.Heur.pmKfrWHPKZoS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.pmKfrWHPKZoS virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Creates known Fynloski/DarkComet mutexes

How to determine Trojan.Heur.pmKfrWHPKZoS?


File Info:

crc32: 75F5C917
md5: 2fe2d2795e65c6a53d7d64c12c6c7c72
name: 4f6d5995a20264ab.exe
sha1: f041908ca02ae66dcfd89de4cb394d8fc3767509
sha256: f7f9df0d90adda6ce5e41e1cc89f39c1f3383ed50f1e51e9e805dc4b526d50b6
sha512: d415d8bf49f659e7314eac3ab341f8d1959b67c8334b1a07e625d542d5162c39c1c44267e501ad43ea30d1b46175fd29d6ce591faf7eb3ed3efe9ee17ad551f3
ssdeep: 6144:VcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQe:VcWkbgTYWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.pmKfrWHPKZoS also known as:

BkavW32.BitwanD.Trojan
DrWebBackDoor.Tordev.9
MicroWorld-eScanGen:Trojan.Heur.pmKfrWHPKZoS
FireEyeGeneric.mg.2fe2d2795e65c6a5
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Trojan.Heur.pmKfrWHPKZoS
K7GWTrojan ( 004bc4d11 )
K7AntiVirusTrojan ( 004bc4d11 )
TrendMicroBKDR_FYNLOS.SMM
BitDefenderThetaAI:Packer.F306402C1C
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.DarkKomet-1
GDataGen:Trojan.Heur.pmKfrWHPKZoS
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.21a37c0b
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
AegisLabTrojan.Win32.DarkKomet.mzOX
RisingBackdoor.Pontoeb!1.6637 (CLOUD)
Endgamemalicious (moderate confidence)
EmsisoftBackdoor.DarkKomet (A)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Backdoor.Agent.l
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
Trapminemalicious.moderate.ml.score
CMCBackdoor.Win32.DarkKomet!O
SophosTroj/Fynlosk-AK
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
ArcabitTrojan.Heur.pmKfrWHPKZoS
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
TACHYONBackdoor/W32.DP-DarkKomet.674816.B
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
MAXmalware (ai score=100)
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
Ad-AwareGen:Trojan.Heur.pmKfrWHPKZoS
AVGFileRepMalware
Cybereasonmalicious.95e65c
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.DarkKomet.B

How to remove Trojan.Heur.pmKfrWHPKZoS?

Trojan.Heur.pmKfrWHPKZoS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment