Trojan

What is “Trojan.Heur.rmKfrG5JCYcS”?

Malware Removal

The Trojan.Heur.rmKfrG5JCYcS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.rmKfrG5JCYcS virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Creates known Fynloski/DarkComet mutexes

Related domains:

astanik2901.ddns.net

How to determine Trojan.Heur.rmKfrG5JCYcS?


File Info:

crc32: D26CA305
md5: e4ec464bf0c3498b3776e7980e0fd0bc
name: 5a90d508e0bc1a0e.exe
sha1: 67ce5076f16fccd0dd54187ae985b54eb6f96a5c
sha256: 9858d8ccab09acf2ba1d06a80085ba7ee42de584dd6f5732c0c90ca34a01a34e
sha512: 2e8dec89b9018e04b7bd732505123b02cc8c5516c2cbdbb446d676c9bb0783846ff0064306766fc78df404eef850433ced800c367e6fd66dadef480b2f767812
ssdeep: 6144:OcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0P69:OcWkbgTYWnYnt/IDYhP69
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.rmKfrG5JCYcS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.Heur.rmKfrG5JCYcS
FireEyeGeneric.mg.e4ec464bf0c3498b
Qihoo-360Win32/Backdoor.DarkKomet.B
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.rmKfrG5JCYcS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.bf0c34
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.45bdbcac
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
AegisLabTrojan.Win32.DarkKomet.m!c
RisingBackdoor.Pontoeb!1.6637 (CLOUD)
Endgamemalicious (moderate confidence)
EmsisoftGen:Trojan.Heur.rmKfrG5JCYcS (B)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.4589
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.DarkKomet!O
SophosTroj/Fynlosk-AK
IkarusTrojan.Win32.Jorik
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
WebrootW32.Rogue.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
ArcabitTrojan.Heur.rmKfrG5JCYcS
SUPERAntiSpywareTrojan.Agent/Gen-Graybird
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32Backdoor.Tordev
Ad-AwareGen:Trojan.Heur.rmKfrG5JCYcS
MalwarebytesBackdoor.Bot
PandaTrj/Genetic.gen
ZonerTrojan.Win32.83985
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
BitDefenderThetaAI:Packer.8E480AFB1C
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureBackdoor.W32.DarkKomet.aagr

How to remove Trojan.Heur.rmKfrG5JCYcS?

Trojan.Heur.rmKfrG5JCYcS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment