Home Malware Programs Trojans TROJ_CARBERP.A

TROJ_CARBERP.A

Posted: October 15, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 956
First Seen: November 30, 2010
Last Seen: July 31, 2018
OS(es) Affected: Windows

TROJ_CARBERP.A is a Trojan which may be downloaded from remote sites by other malware. TROJ_CARBERP.A is downloaded unknowingly by a user when visiting malicious websites, most likely porn sites. TROJ_CARBERP.A injects codes in certain processes and drops files in the Windows User Startup folder to enable its automatic execution at every system startup. TROJ_CARBERP.A also opens ports where it listens for remote commands while hiding files, processes and registry entries. TROJ_CARBERP.A should be removed form the compromised computer immediately using a reliable malware remover.

Aliases

Trj/Genetic.gen [Panda]Generic_r.CES [AVG]W32/Kryptik.WEX!tr [Fortinet]Trojan.Win32.Loktrom [Ikarus]Trojan/Win32.PornoAsset [AhnLab-V3]TR/Dldr.Carberp.A.6 [AntiVir]Gen:Variant.Symmi.19267 [BitDefender]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:Fareit-DZ [Trj] [Avast]Packed.Generic.408 [Symantec]PWS-Zbot.gen.ary [McAfee]Gen:Variant.Symmi.18541 [BitDefender]Trojan-Spy.Win32.Carberp.wpf [Kaspersky]Trojan-Spy.Win32.Carberp.wqy [Kaspersky]Trj/Dtcontx.D [Panda]
More aliases (348)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Start Menu\Programs\Startup\syscron.exe File name: syscron.exe
Size: 79.87 KB (79872 bytes)
MD5: e4f562141b3ff173e4cef9a548b4ae4d
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: November 30, 2010
%USERPROFILE%\Start Menu\Programs\Startup\ntuser_mssec.exe File name: ntuser_mssec.exe
Size: 41.47 KB (41472 bytes)
MD5: f900c82884d9246e4cc36e1a38cd650a
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 7, 2010
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\bgbejXgr1UA.exe File name: bgbejXgr1UA.exe
Size: 230.4 KB (230400 bytes)
MD5: 4f87933b4d943c9ac51ca415c984d966
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\iHZw50qL14E.exe File name: iHZw50qL14E.exe
Size: 253.95 KB (253952 bytes)
MD5: e8d5ceca2af0a8aec1eaf22352e42307
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: April 22, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IwKbUUsOBfQ.exe File name: IwKbUUsOBfQ.exe
Size: 236.03 KB (236032 bytes)
MD5: 85c90b36cf3c0af9c8ee44dac796d7cb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 8, 2013
%USERPROFILE%\Start Menu\Programs\Startup\chkntfs.exe File name: chkntfs.exe
Size: 56.32 KB (56320 bytes)
MD5: 61302b30a920d017bc42472e3e6f0ab5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: February 9, 2011
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Q6G1z0XdKzo.exe File name: Q6G1z0XdKzo.exe
Size: 231.93 KB (231936 bytes)
MD5: 87e69eeae2130c780441abad81e51e0e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 31, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\32ApPxvqErA.exe File name: 32ApPxvqErA.exe
Size: 210.94 KB (210944 bytes)
MD5: 368d99251b7812af3c763aa569e35838
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 28, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\dnaEm6kvVpI.exe File name: dnaEm6kvVpI.exe
Size: 229.88 KB (229888 bytes)
MD5: 60d1b14271be84864eb3afea87e0e36f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: February 25, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\7rfBxbjvPzw.exe File name: 7rfBxbjvPzw.exe
Size: 243.2 KB (243200 bytes)
MD5: 2459e3f960d03102614d6fa484fa1dca
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: February 26, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZYX1vw92ikM.exe File name: ZYX1vw92ikM.exe
Size: 242.17 KB (242176 bytes)
MD5: 6be111586e65d9f275ec6ce267f3acaf
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: March 1, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\9mfjfdjuKwU.exe File name: 9mfjfdjuKwU.exe
Size: 272.38 KB (272384 bytes)
MD5: 6a8563b99e3966e65da303a66ddb098b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: March 6, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SCN9fTYAgvA.exe File name: SCN9fTYAgvA.exe
Size: 322.8 KB (322804 bytes)
MD5: df972a3567cc594b45531bef37c8d03e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: March 12, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\CFjYoQKQiEc.exe File name: CFjYoQKQiEc.exe
Size: 229.88 KB (229888 bytes)
MD5: e995211b7825c4306121961359dd3234
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: April 29, 2013

More files
Loading...