Uhm he is most likely not using Darkcomet or anything of that sort, when i ran it in sandboxie only the .exe process came up, when it is backdoored with a trojan of some sort usually multiple other processes will execute also. But it did get detected 36/40 some on virus total, so I dunno.