Spy Trojan

How to remove “VHO:Trojan-Spy.Win32.Carberp”?

Malware Removal

The VHO:Trojan-Spy.Win32.Carberp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Spy.Win32.Carberp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine VHO:Trojan-Spy.Win32.Carberp?


File Info:

name: 96B8A291AA2B501047A4.mlw
path: /opt/CAPEv2/storage/binaries/7942ae0769b0bc27b8ba28625a1773724f9ae4c3d0d3694fca1e284826e28b44
crc32: 65C91F1A
md5: 96b8a291aa2b501047a4315da1017a9a
sha1: 41833b44b13657a5d6eb8753f3d51eea44de3458
sha256: 7942ae0769b0bc27b8ba28625a1773724f9ae4c3d0d3694fca1e284826e28b44
sha512: aea57e50cd8366f2b2da5709b61c2015860aacf32e7416c550349a5d923077e3943d813116c630558c93038d1be59b7f57d7d1fffb43f4e2b7a071d059f1d18c
ssdeep: 3072:XHeyj/UC940Qt5YhRjaP+pJeS3dZgTj5P6KVw55h:Xeyj5OoL8SeCry1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140C3BE5B354DCA2EE52BC53A471EEDFDFA3F4CA3AB6744572D247C8264B50A01821713
sha3_384: d35a82ebde408fff0ce63aba9abb22b855fb1488dddf3a1b6e3dd3901ec6a4f1c9df0175db0c8c1a65b727258a96dce9
ep_bytes: 60be003042008dbe00e0fdff5783cdff
timestamp: 2007-02-17 00:27:48

Version Info:

CompanyName: MoRUN.net
FileDescription: MoRUN.net Sticker Lite
FileVersion: 6.3
InternalName: Sticker.exe
LegalCopyright: 2002-2010 (c) MoRUN.net. All rights reserved.
OriginalFilename: Sticker.exe
ProductName: MoRUN.net Sticker Lite
ProductVersion: 6.3
Translation: 0x0409 0x04e4

VHO:Trojan-Spy.Win32.Carberp also known as:

BkavW32.MosquitoQKB.Fam.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.VIZ.2
FireEyeGeneric.mg.96b8a291aa2b5010
CAT-QuickHealWorm.SlenfBot.Gen
ALYacGen:Heur.VIZ.2
CylanceUnsafe
ZillyaTrojan.Carberp.Win32.191
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojan:Win32/Ramdo.8742259c
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.1aa2b5
BitDefenderThetaGen:NN.ZexaF.34212.hmKfa8u3KZoc
VirITTrojan.Win32.Scar.NJ
CyrenW32/S-b328bb35!Eldorado
SymantecDownloader.Lofog!gen4
ESET-NOD32a variant of Win32/Kryptik.KHT
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
KasperskyVHO:Trojan-Spy.Win32.Carberp.gen
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.Carberp.ltmvy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Huzg
Ad-AwareGen:Heur.VIZ.2
SophosMal/Generic-R + Mal/FakeAV-BW
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
DrWebTrojan.PWS.Multi.200
VIPRETrojan.Win32.Kryptik.lbu (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Heur.VIZ.2 (B)
APEXMalicious
GDataGen:Heur.VIZ.2
JiangminTrojanSpy.Carberp.fv
WebrootW32.Infostealer.Koobface
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.183A18C
KingsoftWin32.Troj.Carberp.hv.(kcloud)
ViRobotTrojan.Win32.A.Carberp.120832.A[UPX]
MicrosoftTrojan:Win32/Ramdo.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2835
McAfeeArtemis!96B8A291AA2B
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
RisingExploit.ShellCode!8.2A (CLOUD)
YandexTrojanSpy.Carberp!Ki2aLkP1GMM
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Kryptic!tr
AVGWin32:Trojan-gen
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_70% (D)

How to remove VHO:Trojan-Spy.Win32.Carberp?

VHO:Trojan-Spy.Win32.Carberp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment