Trojan

Trojan.RegistryDisabler.pmKfaeBJ7JfS information

Malware Removal

The Trojan.RegistryDisabler.pmKfaeBJ7JfS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RegistryDisabler.pmKfaeBJ7JfS virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz
kackerhost.ddns.net

How to determine Trojan.RegistryDisabler.pmKfaeBJ7JfS?


File Info:

crc32: 35E59C2B
md5: 75fb7d3721fade8de6cdc8b1f81e01b0
name: cheat
sha1: ab93d4fc05c3ee2506213113b5525d34054f4715
sha256: 0604c4fed4d3db60fb225d75e1823b7d321af7850209efcb0af2d69e1e50e520
sha512: 0345a66d6507195c0cdafd11229f7817f1c8eecf8c8e5fd7128418710b6e2b1ccb59ac13ede5e4153eb790574f4a8d17ef06d6e5a22f7de6fd20c57f16410a2a
ssdeep: 6144:IcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQ:IcWkbgTYWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.RegistryDisabler.pmKfaeBJ7JfS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS
CMCBackdoor.Win32.DarkKomet!O
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
MalwarebytesBackdoor.Packed.DK
VIPREBackdoor.Win32.Fynloski.A (v)
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.721fad
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
ClamAVWin.Trojan.DarkKomet-1
GDataGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.23eec7ec
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingBackdoor.Pontoeb!1.6637 (CLASSIC)
Ad-AwareGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS
SophosTroj/Fynlosk-AK
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.742
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.75fb7d3721fade8d
EmsisoftGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS (B)
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
MaxSecureBackdoor.W32.DarkKomet.aagr
AviraBDS/Backdoor.Gen
MAXmalware (ai score=81)
Endgamemalicious (moderate confidence)
ArcabitTrojan.RegistryDisabler.pmKfaeBJ7JfS
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610
Acronissuspicious
VBA32Backdoor.Tordev
ALYacGen:Trojan.RegistryDisabler.pmKfaeBJ7JfS
TACHYONBackdoor/W32.DP-DarkKomet.674304.B
CylanceUnsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
WebrootW32.Trojan.Gen
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.CBA7.Malware.Gen

How to remove Trojan.RegistryDisabler.pmKfaeBJ7JfS?

Trojan.RegistryDisabler.pmKfaeBJ7JfS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment