Threat Database Spyware Win32/Carberp

Win32/Carberp

By JubileeX in Spyware

Win32/Carberp is a spyware that can stealthily enters a system without a user's permission. Win32/Carberp can come bundled with other malware or it can be unknowingly downloaded from corrupt websites. Win32/Carberp is used to monitor a victim's online activities and capture confidential information such as passwords and online banking details. Win32/Carberp may come with a keylogger in order to capture a victim's keystrokes. Systems infected with Win32/Carberp may also experience slow computer speed as the spyware downloads additional malware from a remote server. Win32/Carberp will give a remote attacker unauthorized access to your machine and allow malicious routines to be run in the background. Do not underestimate this threat and have it removed from your system immediately after detecting it.

File System Details

Win32/Carberp may create the following file(s):
# File Name Detections
1. %desktop%\Win32.Carberp.Drp.lnk
2. %commonprograms%\Win32.Carberp.Drp\buy.lnk
3. %commonprograms%\Win32.Carberp.Drp\scan.lnk
4. %programfiles\Win32.Carberp.Drp\about.ico
5. %desktop%\Win32.Carberp.Drp support.lnk
6. %commonprograms%\Win32.Carberp.Drp\activate.lnk
7. %commonprograms%\Win32.Carberp.Drp\Win32.Carberp.Drp.lnk
8. %commonprograms%\Win32.Carberp.Drp\update.lnk
9. %appdata%\microsoft\internet explorer\quick launch\Win32.Carberp.Drp.lnk
10. %commonprograms%\Win32.Carberp.Drp\about.lnk
11. %commonprograms%\Win32.Carberp.Drp\Win32.Carberp.Drp support.lnk
12. %commonprograms%\Win32.Carberp.Drp\settings.lnk
13. %programfiles\Win32.Carberp.Drp\activate.ico

Registry Details

Win32/Carberp may create the following registry entry or registry entries:
hkcu\Software\Microsoft\Windows\CurrentVersion\Run “Win32.Carberp.Drp”
hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win32.Carberp.Drp
hklm\SOFTWARE\Win32.Carberp.Drp
hkcr\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}

Related Posts

Trending

Most Viewed

Loading...