Spy Trojan

UDS:Trojan-Spy.Win32.Carberp removal guide

Malware Removal

The UDS:Trojan-Spy.Win32.Carberp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Carberp virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine UDS:Trojan-Spy.Win32.Carberp?


File Info:

name: 6181F52B91AC595F10BE.mlw
path: /opt/CAPEv2/storage/binaries/f6e5d719bc49954401f58703a1f4e50014a4f43e696a81bc4998728e31c64488
crc32: C2438128
md5: 6181f52b91ac595f10be4c036a8aff8a
sha1: 5a45fe21fec914825e5deabf8b651c7bb346d7e2
sha256: f6e5d719bc49954401f58703a1f4e50014a4f43e696a81bc4998728e31c64488
sha512: b241f12808ba0638ce05f3c0afeabe92994eee1c3ab301ca24193df2290dfc7901979f98ead0fec2391f09c9cab180c2d7b59122a496264bf5c8ac30424c9a11
ssdeep: 12288:5TBGYI2KbfPBAuxlVtD751fpDeEQ5bVf7oK1IkAENz:5ZKbfPBAuxlVtD11hDmZ/6kAEZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA05E006F691C07AC2550030CF95E7B493FAAE7129268807B38C7B4D5A723D7973BB66
sha3_384: b93cd12a8e968ac0a6cd30373c0d6e966385ecbf687092827a5f5dbca94a0ce2850cf434b85f8b7faa2467817c731cb6
ep_bytes: 6a606878864500e88de1ffffbf940000
timestamp: 2009-07-13 09:26:19

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Carberp also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad2.34236
FireEyeGeneric.mg.6181f52b91ac595f
CAT-QuickHealWebTool.GenericNRV.S2074726
MalwarebytesPUP.Optional.Downloader.DDS
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.1fec91
BitDefenderThetaGen:NN.ZexaF.36250.YuY@aKQxDfo
CyrenW32/Zylom.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:Trojan-Spy.Win32.Carberp
NANO-AntivirusTrojan.Win32.Gendal.iebvj
AvastWin32:Evo-gen [Trj]
EmsisoftApplication.Downloader (A)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraGAME/Zylom.Gen5
ZoneAlarmUDS:Trojan-Spy.Win32.Carberp
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!6181F52B91AC
Cylanceunsafe
RisingDownloader.Zylom!1.68C7 (CLASSIC)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.2101081
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove UDS:Trojan-Spy.Win32.Carberp?

UDS:Trojan-Spy.Win32.Carberp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment