Trojan

Trojan:Win32/Comitsproc removal tips

Malware Removal

The Trojan:Win32/Comitsproc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Comitsproc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Comitsproc?


File Info:

crc32: 2F2DA328
md5: c3255af5072e9e0d2459479df605a73f
name: C3255AF5072E9E0D2459479DF605A73F.mlw
sha1: 8881914ba5a33c50a17e9ab86a4e319b8a6b51ae
sha256: f8eecddcd4845e76e98c441a8092bc846b685124e792082e54eaf53b4491fa7a
sha512: 8b1dd8c6768696ecf2c4bf7a658302cd7c7c3ff577d34a7864331de61e91c3a6ace80b5265d7e520e19e6941f049b91db2e89be04e79ef20f4725ad0a9c90d98
ssdeep: 1536:gigXmb9q1WGiMaiSNxIRxv7bvwjjxb1yLzW/h4Tkzcs:vgXmbcZSNxI7T7wj11yHtTxs
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright by Microsoft 2012
Assembly Version: 4.2.4.5
InternalName: jj.exe
FileVersion: 4.1.5.x200b0
CompanyName: Microsoft Corporation
LegalTrademarks: All Rights reserved!
Comments: Windows Messenger
ProductName: Live Messenger
ProductVersion: 4.1.5.x200b0
FileDescription: Windows Live Messenger
OriginalFilename: jj.exe

Trojan:Win32/Comitsproc also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.c3255af5072e9e0d
McAfeeTrojan-FDWX!C3255AF5072E
CylanceUnsafe
ZillyaDropper.FrauDrop.Win32.8844
AegisLabTrojan.Win32.Generic.lVyh
SangforMalware
K7AntiVirusTrojan ( 0048eadf1 )
K7GWTrojan ( 0048eadf1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Razy.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:GenMalicious-CJ [Trj]
ClamAVWin.Trojan.Bladbindi-1
KasperskyTrojan-Dropper.Win32.FrauDrop.acotn
AlibabaTrojanDropper:Win32/FrauDrop.2ef46c9f
NANO-AntivirusTrojan.Win32.Drop.ctqacr
RisingDropper.FrauDrop!8.143 (CLOUD)
SophosMal/Generic-S
ComodoMalware@#1mqqhj1ruh3tf
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.DownLoader10.63222
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FDWX!C3255AF5072E
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan[Dropper]/Win32.FrauDrop
KingsoftWin32.Troj.FrauDrop.(kcloud)
MicrosoftTrojan:Win32/Comitsproc
ZoneAlarmTrojan-Dropper.Win32.FrauDrop.acotn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R138365
BitDefenderThetaGen:NN.ZemsilF.34804.fm0@a8wF9Vn
VBA32TrojanDropper.FrauDrop
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
ESET-NOD32a variant of MSIL/Injector.CET
TencentWin32.Trojan-dropper.Fraudrop.Svgv
IkarusTrojan.Msil
eGambitUnsafe.AI_Score_99%
FortinetW32/FrauDrop.ACOTN!tr
AVGMSIL:GenMalicious-CJ [Trj]
Cybereasonmalicious.ba5a33
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM03.Gen

How to remove Trojan:Win32/Comitsproc?

Trojan:Win32/Comitsproc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment