Home Malware Programs Trojans Trojan.Comquab.A

Trojan.Comquab.A

Posted: June 10, 2011

Trojan.Comquab.A is a variant of the Comquab Trojan that was first seen early in 2011. Trojan.Comquab.A may install itself through several different ways, including through the use of drive-by downloads, being bundled with legitimate updates, and being installed by other Trojans. The Trojan.Comquab.A Trojan is categorized as a dropper that installs other malicious software. Trojan.Comquab.A will directly endanger your PC security, and may even enable remote attackers to control your computer. You should remove Trojan.Comquab.A by using a trustworthy anti-malware program to delete all advanced components.

Why You Might Not See Trojan.Comquab.A Before it's Already on Your PC

Trojan.Comquab.A's installation methods are concealed to avoid your notice, as is typical with Trojans. As a threat that was noticed as recently as February 2011, deleting Trojan.Comquab.A may require recent updates to your browser and security software. Trojan.Comquab.A only has one known close relative, Trojan:Win32/Comquab.B, but Trojan.Comquab.A is closely affiliated with other dropper and spyware Trojans like Trojan:Win32/Chepdu.P, TrojanSpy:Win32/Mafod!rts and Win-Trojan/Atraps.10752.G.

Trojan.Comquab.A's main infection methods include:

  • Being installed by Trojans similar to the ones listed above. These Trojans or Trojan.Comquab.A itself may run in the form of hidden debuggers, or Browser Helper Objects that launch themselves whenever certain applications are used.
  • Being bundled with legitimate security updates and downloads from third-party websites that maliciously alter the package to include Trojan.Comquab.A. Trojan.Comquab.A may be included in the form of an opt-in (check box to install) or opt-out (check box to NOT install) selection. All downloads that include Trojan.Comquab.A can be found without Trojan.Comquab.A from more trustworthy websites.
  • Trojan.Comquab.A may also install itself directly by using drive-by download scripts that are used on malicious sites. You can disable most harmful scripts by keeping JavaScript and Flash blocked for websites that aren't trustworthy.

The Results Once Trojan.Comquab.A Sneaks In

Trojan.Comquab.A is classified as a dropper, and accordingly, may install any number of other harmful infections. Many droppers like Trojan.Comquab.A are known for installing rogue security programs that pretend to be anti-virus utilities, while creating fake alerts. Other Trojan droppers can install a hidden Remote Administration Tool software that lets remote attackers control your PC.

Given its noted proclivity for BHO antics, Trojan.Comquab.A is particularly likely to perform spyware or browser hijacker functions. Spyware can record and steal passwords and other sensitive information, while hijacks will alter your online content, and redirect you from safe websites to unsafe ones. A Trojan.Comquab.A hijacker can even imitate a standard browser's fake error page.

The complexity of possible .dll files and other components related to Trojan.Comquab.A mean that manually deleting Trojan.Comquab.A's files is a challenging ordeal. The easiest solution is to utilize a good anti-malware program, although you should verify that Trojan.Comquab.A isn't running, before any attempts to remove Trojan.Comquab.A from your PC.

Safe Mode is the preferred method for dealing with active Trojans like Trojan.Comquab.A, although more extreme circumstances may necessitate booting your computer from a CD.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 api-ms-win-core-libraryloader-l1-1-032.dll
    2 api-ms-win-core-misc-l1-1-032.dll
    3 atl32.dll
    4 AudioSes32.dll
    5 avmeter32.dll
    6 cliconfg32.dll
    7 credui3232.dll
    8 CTAPO3232.dll
    9 ctfmon_fn.exe
    10 ctfmon_ox.exe
    11 ctfmondmf.exe
    12 ctfmonhvj.exe
    13 ctfmonjlj.exe
    14 ctfmonnlk.exe
    15 ctfmonqni.exe
    16 ctfmonryw.exe
    17 ctfmonwkt.exe
    18 dbghelp32.dll
    19 ixsso32.dll
    20 msrecr4032.dll
    21 Qwiqib.exe
    22 setup_2013_ibr8.exe
Loading...