Trojan

About “Trojan:MSIL/DarkComet.ADA!MTB” infection

Malware Removal

The Trojan:MSIL/DarkComet.ADA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/DarkComet.ADA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings

How to determine Trojan:MSIL/DarkComet.ADA!MTB?


File Info:

name: 52A92A076B73155AFD5C.mlw
path: /opt/CAPEv2/storage/binaries/0af08b7da6dcd2f7a340fc7cddc914d16752462a25087fa432642dc4bf47219a
crc32: C1867DE5
md5: 52a92a076b73155afd5c1d58eb50f1c1
sha1: 0ad1d50838e8435c934c556ed49da9bd17e5b7b5
sha256: 0af08b7da6dcd2f7a340fc7cddc914d16752462a25087fa432642dc4bf47219a
sha512: b334428fcf178cf29f10ae275c5aa561b27c56e89b4f0b80e491174e332fd62ae5e021e111aefca4ae6e2a300699ca6072d7ae2acaf52066eba5e7a5d5d16f5d
ssdeep: 24576:YZSdEB3dyFPEl+8NrVhKsGypUZiksZC1:z+tKyBrrqZl2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F15ADE96F741D30E1DFA1792B516A8E9C79AE0A329FF00B4BBBAA400455BFF745D040
sha3_384: 92cba06b3b9feaab24c919decbdbcc8578d264953fb89ed5ea8caafc0dd217fd90e5f9968514f78dbc77e50330878bfb
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-05-05 14:40:50

Version Info:

Comments: SteamAutoAcceptor
CompanyName: SteamSlayer
FileDescription: AutoAcceptor
FileVersion: 13.0.6.66
InternalName: xcom.exe
LegalCopyright: SteamSlayer
LegalTrademarks: SteamSlayer
OriginalFilename: SteamAutoAcceptor.exe
ProductName: AutoAcceptor
ProductVersion: 1.0.0
Assembly Version: 1.0.0
Translation: 0x0000 0x04b0

Trojan:MSIL/DarkComet.ADA!MTB also known as:

BkavW32.AIDetectMalware.CS
AVGMSIL:Banker-AG [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader13.11722
MicroWorld-eScanGen:Variant.Lazy.97824
FireEyeGeneric.mg.52a92a076b73155a
SkyhighGenericRXKT-EM!52A92A076B73
McAfeeGenericRXKT-EM!52A92A076B73
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
BitDefenderThetaGen:NN.ZemsilF.36802.6m0@ayvk2Thi
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.JNF
APEXMalicious
AvastMSIL:Banker-AG [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.97824
NANO-AntivirusTrojan.Win32.Dwn.dztjyi
SophosML/PE-A
VIPREGen:Variant.Lazy.97824
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Lazy.97824 (B)
JiangminBackdoor/DarkKomet.jnq
WebrootW32.Email.Worm.Silly
MAXmalware (ai score=82)
Antiy-AVLHackTool[VirTool]/MSIL.Obfuscator
MicrosoftTrojan:MSIL/DarkComet.ADA!MTB
XcitiumBackdoor.MSIL.Androm.GI@5qldz0
ArcabitTrojan.Lazy.D17E20
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Lazy.97824
GoogleDetected
ALYacGen:Variant.Lazy.97824
VBA32TScope.Trojan.MSIL
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:DX3I5PXOUaMKdBN++zWQ7g)
IkarusTrojan.Hesv
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.JNF!tr
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/DarkComet.ADA!MTB?

Trojan:MSIL/DarkComet.ADA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment