Backdoor.Carool is a Backdoor Trojan horse that allows unauthorized remote access your computer.
The Trojan also installs a keylogger and steals cached passwords.
Creates the following files:
%System%\OTCXXH.EXE
%System%\zpvkkom.dll
%System%\fpxjjgd.dll
%System%\keussm.dll
%System%\bdphhwls.tmp
Executes the OTCXXH.EXE file.
Adds the value: "otcx"="%System%\otcxxh.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Connects to a predetermined URL and uploads a keystroke log.
Listens for connections from the remote attacker on random TCP ports.
If they connect, an attacker can perform any of these following actions:
- Logs keystrokes
- Steals .pwl files
- Opens and closes the CD-ROM drive
RegRun Startup Optimizer will help you to remove this trojan.
Removal: otcxxh.exe is removed by RegRun.
Read more... Removal instructions...
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
September 1 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?