Trojan

Trojan.Heur.tmKfrex5K8pS information

Malware Removal

The Trojan.Heur.tmKfrex5K8pS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.tmKfrex5K8pS virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

Related domains:

nemoneyron.ddns.net

How to determine Trojan.Heur.tmKfrex5K8pS?


File Info:

crc32: 4EB7EB1C
md5: 0c8a0bcf335d7884ff7be43e162a1268
name: 0C8A0BCF335D7884FF7BE43E162A1268.mlw
sha1: ad327f25b0635d5d7c3c20f6dc53826845686f7e
sha256: fbc3d8b3e9ec4932d066a8f9ceb7c8d654c9addbb97f4fe0307695a6d4980c59
sha512: 49639cb69c706be5e6b4cac66af2182ff9542f9ff804349855244c15c588bd3fbf5d619b529e3e6a133731740e3034be04848e21e32afe46e6d4273bfcb0da0b
ssdeep: 6144:NcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PEk/5KRC:NcWkbgTYWnYnt/IDYhPEvC
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Heur.tmKfrex5K8pS also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.tmKfrex5K8pS
FireEyeGeneric.mg.0c8a0bcf335d7884
CAT-QuickHealBackdoor.Fynloski.A9
Qihoo-360HEUR/QVM19.1.3A86.Malware.Gen
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.tmKfrex5K8pS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.f335d7
TrendMicroHT_DARKKOMET_GA310EF6.UVPM
BitDefenderThetaAI:Packer.1C5D21681C
CyrenW32/Darkkomet.A.gen!Eldorado
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
BaiduWin32.Backdoor.Agent.l
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingWorm.Fasong!1.A8B5 (TFE:3:TE7kAJ6r0EF)
Ad-AwareGen:Trojan.Heur.tmKfrex5K8pS
EmsisoftTrojan.Fynloski (A)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
InvinceaML/PE-A + Troj/Fynlosk-AK
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
SophosTroj/Fynlosk-AK
IkarusBackdoor.Win32.DarkKomet
JiangminTrojan/Genome.bomw
AviraBDS/Backdoor.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
GridinsoftBackdoor.Win32.Fynloski.zv!n
ArcabitTrojan.Heur.tmKfrex5K8pS
SUPERAntiSpywareBackdoor.DarkKomet/Variant
AhnLab-V3Win-Trojan/FCN.140610.X1341
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
GDataWin32.Trojan-Spy.DarkComet.J
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Fynloski.AN
Acronissuspicious
VBA32Backdoor.Tordev
TACHYONBackdoor/W32.DP-DarkKomet.742400.D
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.88734
TrendMicro-HouseCallHT_DARKKOMET_GA310EF6.UVPM
YandexTrojan.Comet.Gen.LO
SentinelOneStatic AI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureBackdoor.W32.DarkKomet.aagr

How to remove Trojan.Heur.tmKfrex5K8pS?

Trojan.Heur.tmKfrex5K8pS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment