Trojan

Trojan.UserStartup.rmKfaCZBYOlS removal instruction

Malware Removal

The Trojan.UserStartup.rmKfaCZBYOlS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.UserStartup.rmKfaCZBYOlS virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
fredbaty.hopto.org
a.tomx.xyz

How to determine Trojan.UserStartup.rmKfaCZBYOlS?


File Info:

crc32: 484AF642
md5: 32eb8456a3261bcd3e639d98a48ff9fd
name: kaxa.exe
sha1: e7c149cfe8c76645e293d5ffbf404234f0e7fbb5
sha256: 79b170349c302c81f377452c2402df22301b6631fb1903254fd23e56993f3779
sha512: 963123e2b5484758972e7c2fb2651cecbf394578d1b254dfb230a4960b59233c1980e4df3c805160f79a5cc7b3af4e605d4e1f721aaab46c0174925f385fc1d4
ssdeep: 6144:ZcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PD:ZcWkbgTYWnYnt/IDYhPD
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.UserStartup.rmKfaCZBYOlS also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Trojan.UserStartup.rmKfaCZBYOlS
FireEyeGeneric.mg.32eb8456a3261bcd
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.UserStartup.rmKfaCZBYOlS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.6a3261
Invinceaheuristic
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.DarkKomet-1
GDataGen:Trojan.UserStartup.rmKfaCZBYOlS
KasperskyBackdoor.Win32.DarkKomet.gwbu
AlibabaBackdoor:Win32/DarkKomet.6b83095c
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingBackdoor.Pontoeb!1.6637 (CLASSIC)
Ad-AwareGen:Trojan.UserStartup.rmKfaCZBYOlS
SophosTroj/Fynlosk-AK
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
ZillyaTrojan.Fynloski.Win32.742
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.DarkKomet!O
EmsisoftGen:Trojan.UserStartup.rmKfaCZBYOlS (B)
IkarusTrojan.Win32.Jorik
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
MaxSecureBackdoor.W32.DarkKomet.aagr
AviraBDS/Backdoor.Gen
MAXmalware (ai score=80)
Endgamemalicious (moderate confidence)
ArcabitTrojan.UserStartup.rmKfaCZBYOlS
SUPERAntiSpywareTrojan.Agent/Gen-Graybird
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
AhnLab-V3Win-Trojan/FCN.140610
Acronissuspicious
BitDefenderThetaAI:Packer.1342AC501C
ALYacGen:Trojan.UserStartup.rmKfaCZBYOlS
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Bot
PandaTrj/Genetic.gen
ZonerTrojan.Win32.83985
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
WebrootW32.Rogue.Gen
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.2FB1.Malware.Gen

How to remove Trojan.UserStartup.rmKfaCZBYOlS?

Trojan.UserStartup.rmKfaCZBYOlS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment