Home Malware Programs Trojans TrojanDownloader:Win32/Carberp.C

TrojanDownloader:Win32/Carberp.C

Posted: September 6, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 1,497
First Seen: November 30, 2010
OS(es) Affected: Windows

TrojanDownloader:Win32/Carberp.C is a malicious Trojan that stealthily downloads and installs additional malware threats without a user's permission. When executed, TrojanDownloader:Win32/Carberp.C copies itself to the particular locations and creates files on an infected computer system. TrojanDownloader:Win32/Carberp.C may contact a remote host using port 80 for malicious purposes, which include reporting a new threat to its author, uploading data stolen from the infected computer, receiving instructions from remote attackers, receiving configuration or other data, and downloading and executing arbitrary files (as well additional malware or updates). You should remove TrojanDownloader:Win32/Carberp.C immediately with a strong anti-spyware program.

Aliases

PSW.Generic9.BMLK [AVG]W32/Rorpian.C!tr [Fortinet]TROJ_GEN.RFFC7BK [TrendMicro]TR/Offend.KD.534464 [AntiVir]Trojan-Spy.Win32.Carberp.dym [Kaspersky]Win32:Agent-AOCY [Trj] [Avast]a variant of Win32/Kryptik.AAXR [NOD32]Generic.dx!bd3q [McAfee]Worm/Generic2.CLEC [AVG]W32/Zbot.EQPB!tr [Fortinet]Virus.Win32.Cryptor [Ikarus]TR/Dldr.Carberp.C.548 [AntiVir]Trojan.Necurs.20 [DrWeb]Trojan-Ransom.Win32.Blocker.hvr [Kaspersky]Win32:Trojan-gen [Avast]
More aliases (479)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Start Menu\Programs\Startup\eiJhDZy94Vo.exe File name: eiJhDZy94Vo.exe
Size: 151.04 KB (151040 bytes)
MD5: e703d52e70cdbdb89e14495931d232ad
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: March 21, 2013
%USERPROFILE%\Start Menu\Programs\Startup\EuTHLWgFQr8.exe File name: EuTHLWgFQr8.exe
Size: 197.12 KB (197121 bytes)
MD5: 0b36e174461a831a11456f3b33afa578
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 27, 2012
C:\U.exe File name: U.exe
Size: 29.69 KB (29696 bytes)
MD5: 5836d0ecb9d4b0fab8cbfef148d1773e
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Path: C:
Group: Malware file
Last Updated: December 7, 2010
%USERPROFILE%\Start Menu\Programs\Startup\igfxtray.exe File name: igfxtray.exe
Size: 220.67 KB (220672 bytes)
MD5: 03c50185997327fbd5e0fc6e76a78d0d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 27, 2011
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\at9TNeXEYtU.exe File name: at9TNeXEYtU.exe
Size: 199.68 KB (199681 bytes)
MD5: 1dd83e7151ecc4ffb2806cf3e9bac423
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\5y2JVnwMmpc.exe File name: 5y2JVnwMmpc.exe
Size: 195.58 KB (195585 bytes)
MD5: a5e72f333b80d58a1bb4d5f70a7ca3da
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 28, 2012
C:\Documents and Settings\<username>\local settings\temp\~tm12.tmp File name: C:\Documents and Settings\<username>\local settings\temp\~tm12.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\~tm13.tmp File name: C:\Documents and Settings\<username>\local settings\temp\~tm13.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\10.tmp File name: C:\Documents and Settings\<username>\local settings\temp\10.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\11.tmp File name: C:\Documents and Settings\<username>\local settings\temp\11.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\e.tmp File name: C:\Documents and Settings\<username>\local settings\temp\e.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\f.tmp File name: C:\Documents and Settings\<username>\local settings\temp\f.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\Documents and Settings\<username>\start menu\programs\startup\msconfig32.exe File name: C:\Documents and Settings\<username>\start menu\programs\startup\msconfig32.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\igfxtray.dat File name: %AppData%\igfxtray.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\wndsksi.inf File name: %AppData%\wndsksi.inf
Mime Type: unknown/inf
Group: Malware file
%Temp%\6.tmp File name: %Temp%\6.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%Temp%\62.tmp File name: %Temp%\62.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%Programs%\Startup\igfxtray.exe File name: %Programs%\Startup\igfxtray.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 1609 =HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 1609 =
Loading...