Trojan-Spy.Carberp

By CagedTech in Keyloggers

Threat Scorecard

Ranking: 36
Threat Level: 90 % (High)
Infected Computers: 1,039,413
First Seen: October 19, 2012
Last Seen: February 2, 2024
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan-Spy.Carberp

File System Details

Trojan-Spy.Carberp may create the following file(s):
# File Name MD5 Detections
1. cloudnet.exe 8d61e6f9259b0505935b818142893f7b 404
2. winupdate.exe 4dfba34cb266322c7018fa17755883d0 150
3. nvid_upd.exe e26f6ca898e41be9399509f74599a375 18
4. cloudnet.exe 4772f9c1ba4ff73a1a1ef0ed95126fc7 13
5. cloudnet.exe 019e9bf69a353966f30456f012b25f2f 9
6. nvid_upd.exe 2db2127372ec2d19cf019b54353b6c01 8
7. rdpinst.exe 215265e6464bf57c71e57c4e9d445602 8
8. cloudnet.exe 6da7616252369d9a47c7e1408bfff433 8
9. nvid_upd.exe 1796743828a828689fb5a4a3f34853f8 7
10. cloudnet.exe bc92af8aa078b154bcedbed79345a7e5 7
11. cloudnet.exe 2300c45ff5f7fecc5d1e81d0fa0de46d 7
12. cloudnet.exe d15cd3ec8c1f63b108d70e42550ca865 7
13. cloudnet.exe 16730b17d31419b06784364b96bec88d 7
14. cloudnet.exe 5708e29db49e7fc7420f0b68a9611e5e 7
15. cloudnet.exe 0f20a68dcb4bc9e81ab22b8ebd4fa3a9 7
16. aaa.exe 11bba9b2333559b727caf22896092217 6
17. cloudnet.exe 08b56c78f5a54071f99444e0713843f7 5
18. rdpinst.exe 9f9c9f627942f3e658d45ab1481c2ed5 3
19. cloudnet.exe 39c8efd5f1bc28b3f96c05f99581180f 3
20. cloudnet.exe ec4559dea9ec3349d2a9c5087a8fc864 3
21. cloudnet.exe ee75b4671827358a44e9a6e2262583e5 3
22. cloudnet.exe fe4865780c7aa390edfd68212e270243 3
23. rdpinst.exe 7ce237a218fa73045d89e79d19c889c4 2
24. rdpinst.exe d4609d4a98cc1c2048599be77f3502e8 1
25. rdpinst.exe 6f88de861f2edf6757d2027ec4503257 1
26. rdpinst.exe 8c70d50e12e7948632fedf8ace299ee9 1
27. rdpinst.exe 365e42fc0253a372c397759ee5cd941f 1
28. rdpinst.exe 22a202f749c18edbef9b1a6d40f56e21 1
29. rdpinst.exe 0c5d583716aebfc429958c5e2969fb1e 1
More files

Registry Details

Trojan-Spy.Carberp may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\B1_[RANDOM CHARACTERS].bat
%APPDATA%\G1_[RANDOM CHARACTERS].exe
%LOCALAPPDATA%\Microsoft\Windows\winupdate.exe
%userprofile%\Local Settings\Application Data\NVIDIA Corporation\Update\nvupd32.exe
%WINDIR%\rdpinst.exe
%WINDIR%\System32\com\svchost.exe
%WINDIR%\System32\drivers\WinmonSystemMonitor.sys
Software\EpicNet Inc.
SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes\cloudnet.exe
SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes\greenbird.exe
SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes\windefender.exe
Software\Microsoft\Windows\CurrentVersion\Run\CloudNet
Software\Microsoft\Windows\CurrentVersion\Run\DivineWind
Software\Microsoft\Windows\CurrentVersion\Run\GreenBird
Software\Microsoft\Windows\CurrentVersion\Run\LongWind
SOFTWARE\Policies\Microsoft\Windows\safer\CloudMedia
SOFTWARE\Wow6432Node\Policies\Microsoft\Windows\safer\CloudMedia
SYSTEM\ControlSet001\services\WinDefender
SYSTEM\ControlSet002\services\WinDefender
SYSTEM\CurrentControlSet\services\WinDefender

Directories

Trojan-Spy.Carberp may create the following directory or directories:

%appdata%\EpicNet Inc
%appdata%\EpicNet Inc.

1 Comment

r2s.yawm.online Reply

thank you for information

Trending

Most Viewed

Loading...