Associated Malware Groups
The filename is associated with the malware groups:
- Spyware
- Cloaked Malware
- Worm
File Behavior
COMCA.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Found on infected systems and resists interrogation by security products
- Enables an In Process Object/Server - Common with DLL Injections
COMCA.DLL has been the subject of the following behavior:
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Enabled as an In Process Object/Server - Common with DLL Injections
- Created as a process on disk
Country Of Origin
The filename COMCA.DLL was first seen on Nov 24 2007 in the following geographical regions of the Webroot community:
- The United States on Nov 24 2007
- Italy on Nov 24 2007
- Spain on Jul 15 2008
- Romania on Nov 28 2008
- Hong Kong on Nov 28 2008
Filesizes
The following file size has been seen:
- 97,280 bytes
- 91,648 bytes
- 96,256 bytes
- 95,744 bytes
- 125,952 bytes
- 83,456 bytes
- 104,186 bytes
- 118,528 bytes
File Type
The filename COMCA.DLL refers to many versions of a dynamic link library.
File Activity
One or more files with the name COMCA.DLL creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\system32\ipv6mopk.dl_
- Moves c:\windows\system32\ipv6mopk.dll to c:\windows\system32\ipv6mopk.dl_
- Deletes c:\windows\system32\ipv6mote.dl_
- Moves c:\windows\system32\ipv6mote.dll to c:\windows\system32\ipv6mote.dl_
- Deletes c:\windows\system32\ipv6mons.dl_
- Moves c:\windows\system32\ipv6mons.dll to c:\windows\system32\ipv6mons.dl_
- Deletes c:\windows\system32\ipv6monl.dl_
- Moves c:\windows\system32\ipv6monl.dll to c:\windows\system32\ipv6monl.dl_
- Deletes c:\windows\system32\AClient.dl_
- Moves c:\windows\system32\AClient.dll to c:\windows\system32\AClient.dl_
- Deletes c:\windows\system32\ipv6monq.dl_
- Moves c:\windows\system32\ipv6monq.dll to c:\windows\system32\ipv6monq.dl_
- Deletes c:\windows\system32\ipv6mopz.dl_
- Moves c:\windows\system32\ipv6mopz.dll to c:\windows\system32\ipv6mopz.dl_
- Deletes c:\windows\system32\ipv6mops.dl_
- Moves c:\windows\system32\ipv6mops.dll to c:\windows\system32\ipv6mops.dl_
- Deletes c:\windows\system32\ipv6motp.dl_
- Moves c:\windows\system32\ipv6motp.dll to c:\windows\system32\ipv6motp.dl_
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.