Trojan

Trojan.Heur.qmKfrG4ZQQmS removal instruction

Malware Removal

The Trojan.Heur.qmKfrG4ZQQmS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.qmKfrG4ZQQmS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
bondar123.ddns.net
a.tomx.xyz

How to determine Trojan.Heur.qmKfrG4ZQQmS?


File Info:

crc32: 235D9FDE
md5: 891a52a069ff0c5d54a9e95da323f5a2
name: wifi_vanya.exe
sha1: 88aea06acb1ed054ad88de8fcb544e596b5f1f50
sha256: ee687e8742a2bd97d2935b74aada94ec8027ac64bcb3b8cd3e46b3a6af8d16bd
sha512: 4371c6170e6035d75cdb27a11eb3fbce4501cd24f8704ae3814c4b7e742dfef511a4d74026b05c61764d623a94d9816b36a1aa2223ac6444c7c8af3c7be4230a
ssdeep: 6144:5cNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PtF2:5cWkbgTYWnYnt/IDYhPr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.qmKfrG4ZQQmS also known as:

BkavW32.BitwanD.Trojan
DrWebBackDoor.Tordev.9
MicroWorld-eScanGen:Trojan.Heur.qmKfrG4ZQQmS
FireEyeGeneric.mg.891a52a069ff0c5d
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
MalwarebytesBackdoor.Packed.DK
VIPREBackdoor.Win32.Fynloski.A (v)
AegisLabTrojan.Win32.DarkKomet.m!c
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.qmKfrG4ZQQmS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.069ff0
TrendMicroBKDR_FYNLOS.SMM
BitDefenderThetaAI:Packer.38EA7F0E1C
CyrenW32/Fynloski.FWDO-2352
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.1317a7f9
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
TencentBackdoor.Win32.DarkKomet.zem
Ad-AwareGen:Trojan.Heur.qmKfrG4ZQQmS
SophosTroj/Fynlosk-AK
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Backdoor.Agent.l
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.DarkKomet!O
EmsisoftGen:Trojan.Heur.qmKfrG4ZQQmS (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Fynloski.BA
JiangminTrojan/Genome.bomw
MaxSecureBackdoor.W32.DarkKomet.aagr
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Endgamemalicious (moderate confidence)
ArcabitTrojan.Heur.qmKfrG4ZQQmS
SUPERAntiSpywareBackdoor.Fynloski/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32Backdoor.Tordev
CylanceUnsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.88734
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.Pontoeb!1.6637 (CLOUD)
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
AVGFileRepMalware
AvastMSIL:GenMalicious-CHX [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.DarkKomet.B

How to remove Trojan.Heur.qmKfrG4ZQQmS?

Trojan.Heur.qmKfrG4ZQQmS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment