Trojan

How to remove “Trojan.Heur.smKfruYSJEcS”?

Malware Removal

The Trojan.Heur.smKfruYSJEcS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.smKfruYSJEcS virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Creates known Fynloski/DarkComet mutexes

How to determine Trojan.Heur.smKfruYSJEcS?


File Info:

crc32: 8E5E8290
md5: 4f7595d81e019883291f30db9183471f
name: 2fb7cb2020809c8b.scr
sha1: d558df57bce634fa46e892701ae30fe9f67d4b88
sha256: 98dda5af0bfded77914a5374697482cd840ac98525bbb43c31a166b9c5c0ef98
sha512: d8ea5baaedbcb9a80cc35e1314e1287baea26c6a42a33b0d1380f07560fb0b9d2199d1c824eb675178f609d2f851823a0bffbc7023bd0f1e69e6fe1b41804092
ssdeep: 6144:TcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PDd:TcWkbgTYWnYnt/IDYhPDd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.smKfruYSJEcS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.Heur.smKfruYSJEcS
FireEyeGeneric.mg.4f7595d81e019883
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.smKfruYSJEcS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.81e019
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
TencentBackdoor.Win32.DarkKomet.zem
Endgamemalicious (moderate confidence)
SophosTroj/Fynlosk-AK
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.DarkKomet!O
EmsisoftGen:Trojan.Heur.smKfruYSJEcS (B)
IkarusTrojan.Win32.Jorik
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
AviraBDS/Backdoor.Gen
ArcabitTrojan.Heur.smKfruYSJEcS
SUPERAntiSpywareBackdoor.Fynloski/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32Backdoor.Tordev
MAXmalware (ai score=81)
Ad-AwareGen:Trojan.Heur.smKfruYSJEcS
MalwarebytesBackdoor.Bot
PandaTrj/Genetic.gen
ZonerTrojan.Win32.88734
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.Pontoeb!1.6637 (CLASSIC)
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
BitDefenderThetaAI:Packer.50E3DDA31C
AVGMSIL:GenMalicious-CHX [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.6B58.Malware.Gen

How to remove Trojan.Heur.smKfruYSJEcS?

Trojan.Heur.smKfruYSJEcS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment