Trojan

Trojan:Win32/Comame removal guide

Malware Removal

The Trojan:Win32/Comame is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Comame virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Comame?


File Info:

crc32: CA4185D2
md5: e2584ca10236a6303c6bbdc4cac233bc
name: E2584CA10236A6303C6BBDC4CAC233BC.mlw
sha1: 7c1f25c28329f280ca405001c3335e797032da8e
sha256: d61bc60166e5a6f059c39ab374316f386d7193d0c0946a138aa6ae1b9b868226
sha512: 0e6f1b9d18335bb775603975f73f9f619de77c04013846ee76b470499f3db574aa66e367766e046868731b727e08f4a8b1eb474ede41d70aebca05ca85113a38
ssdeep: 12288:gXmwRo+mv8QD4+0N46BoVAoo32zrzP5xd32mE1bPqnx38vmQdz:gX48QE+ULoyo13FL3Gdyy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Adobe Systems.inc
FileDescription: Adobe Flash Video 3 Installation
FileVersion: 3
Comments:
CompanyName: Adobe Systems.inc
Translation: 0x0409 0x04e4

Trojan:Win32/Comame also known as:

K7AntiVirusTrojan ( 7000000f1 )
DrWebTrojan.Encoder.102
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.28329f
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyUDS:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.exziru
TencentWin32.Trojan.Rector.Ahxw
SophosMal/Generic-S
ComodoMalware@#7pjnaxmsmzba
BitDefenderThetaGen:NN.ZexaF.34170.yuZ@aOBRLgfc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.e2584ca10236a630
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1132730
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2476AB0
MicrosoftTrojan:Win32/Comame
ZoneAlarmHEUR:Trojan.Win32.Generic
McAfeeArtemis!E2584CA10236
VBA32TScope.Malware-Cryptor.SB
PandaTrj/CI.A
YandexTrojan.Encoder!zxGJeJxy0Ow
IkarusTrojan-PWS.Win32.Tepfer
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Filecoder.AD
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan:Win32/Comame?

Trojan:Win32/Comame removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment