Trojan

Trojan:Win32/Carmapic.A malicious file

Malware Removal

The Trojan:Win32/Carmapic.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Carmapic.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Carmapic.A?


File Info:

crc32: E3B228D6
md5: 1c4a84daacf0eb118cdf19cec36a2c8b
name: 1C4A84DAACF0EB118CDF19CEC36A2C8B.mlw
sha1: 494548fb7c53a0df1a9a233cf8341715ca0d842b
sha256: 8ba00c90b2b61fa904aa864c13d625f39e411ef0bf4a9cd5b1b3c8ca142d088d
sha512: 4e5b0818f0f16bc4643001bb046b8ce068417b89f5c6224eb3174589c55a20b3dcb209e475c52f2eaeb83bdd9e554913efffcd4a78db843ed0cef5f83872b04e
ssdeep: 6144:pDghuZIekH3D9Tegm6dleNXi5M6GRqfisa/5OU:pDgEOe89Tpm6DeNXZ6GIfi95O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Carmapic.A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.PinkBlocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.1270
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.63449
CylanceUnsafe
ZillyaTrojan.PinkBlocker.Win32.840
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Carmapic.c42c162a
Cybereasonmalicious.aacf0e
CyrenW32/Risk.ZDFT-7190
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DQU
APEXMalicious
AvastWin32:MalOb-AR [Cryp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.63449
NANO-AntivirusTrojan.Win32.Winlock.dfaklc
MicroWorld-eScanGen:Variant.Barys.63449
TencentWin32.Trojan.Generic.Dzao
Ad-AwareGen:Variant.Barys.63449
SophosML/PE-A + Mal/EncPk-AAT
ComodoTrojWare.Win32.PkdKrap.Gx@27uldg
BitDefenderThetaAI:Packer.27891C161E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_KRAP.SMGS
McAfee-GW-EditionNew Malware.ko
FireEyeGeneric.mg.1c4a84daacf0eb11
EmsisoftGen:Variant.Barys.63449 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PinkBlocker.nz
WebrootTrojan:Win32/Carmapic.A
AviraTR/Dropper.Gen
eGambitGeneric.Trojan
Antiy-AVLTrojan/Generic.ASMalwS.1079E78
MicrosoftTrojan:Win32/Carmapic.A
GDataGen:Variant.Barys.63449
Acronissuspicious
McAfeeArtemis!1C4A84DAACF0
MAXmalware (ai score=99)
VBA32Trojan.Waledac.42
PandaTrj/Krapack.gen
TrendMicro-HouseCallTROJ_KRAP.SMGS
RisingTrojan.Generic@ML.100 (RDML:3DciiMeb9lrKT/je8Ud/Bw)
YandexTrojan.PinkBlocker!SicKLbe0Tm4
IkarusTrojan.Win32.Carmapic
FortinetW32/Krap.HM!tr
AVGWin32:MalOb-AR [Cryp]
Qihoo-360Win32/TrojanDropper.Generic.HxQBEpsA

How to remove Trojan:Win32/Carmapic.A?

Trojan:Win32/Carmapic.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment