Trojan

Trojan.Heur.rmKfriUYFUgS malicious file

Malware Removal

The Trojan.Heur.rmKfriUYFUgS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.rmKfriUYFUgS virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

Related domains:

shokerman.ddns.net

How to determine Trojan.Heur.rmKfriUYFUgS?


File Info:

crc32: 230FEFF9
md5: d8a6437ae651cfad40e3f84612254bcb
name: setup_2.exe
sha1: 9009dd2f8d12113df61548912d32b98c9b23fc39
sha256: 2b9c6ae0f981ac57f65c8e8c1d51546bc44b1414871ecc6e49b58bed7cf60ae5
sha512: ac212c7711783b83c540ece5c3f19d47023cd3fb6f4c7c48499ebf20f8cf6595a8148cd9dd53683a81852356a10b85c79d2db9004827fdeaf561f0476461ec78
ssdeep: 6144:dcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PA:dcWkbgTYWnYnt/IDYhPA
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.rmKfriUYFUgS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.Heur.rmKfriUYFUgS
CMCBackdoor.Win32.DarkKomet!O
CAT-QuickHealBackdoor.Fynloski.A9
Qihoo-360HEUR/QVM11.1.264F.Malware.Gen
MalwarebytesBackdoor.Bot
VIPREBackdoor.Win32.Fynloski.A (v)
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.rmKfriUYFUgS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.ae651c
ArcabitTrojan.Heur.rmKfriUYFUgS
BaiduWin32.Backdoor.Agent.l
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
CyrenW32/Fynloski.FWDO-2352
ESET-NOD32a variant of Win32/Fynloski.AN
APEXMalicious
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.gwbu
SUPERAntiSpywareTrojan.Agent/Gen-Graybird
TencentBackdoor.Win32.DarkKomet.zem
Ad-AwareGen:Trojan.Heur.rmKfriUYFUgS
EmsisoftGen:Trojan.Heur.rmKfriUYFUgS (B)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
FortinetW32/Generic.AC.DB56!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d8a6437ae651cfad
SophosTroj/Fynlosk-AK
F-ProtW32/Fynloski.BA
JiangminTrojan/Genome.bomw
MAXmalware (ai score=84)
Endgamemalicious (moderate confidence)
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
AhnLab-V3Win-Trojan/FCN.140610
Acronissuspicious
McAfeeGeneric.gj
TACHYONBackdoor/W32.DP-DarkKomet.707072
VBA32Backdoor.Tordev
CylanceUnsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.28488
RisingBackdoor.Pontoeb!1.6637 (RDM+:cmRtazrA5nJdYXM+wf1JtO4O9H3A)
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
GDataWin32.Backdoor.Fynloski.F
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureBackdoor.W32.DarkKomet.aagr

How to remove Trojan.Heur.rmKfriUYFUgS?

Trojan.Heur.rmKfriUYFUgS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment