This detection is for software that uses a particular SSL hijacker designed by Komodia. The hijacker is vulnerable to man-in-the-middle (MITM) attacks. This is hidden from users using a special rootkit. At the time when this was revealed, the SSL hijack is also called “Superfish”.

Common infection method

This rootkit comes with many aggressive adware programs. Some of these were pre-installed on certain brands of computers.


Malwarebytes can remove Rootkit.Komodia.PUA without further user interaction. You will almost always see several PUP or adware detection alongside.

