Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
CTBR(1).DLL has been seen to perform the following behavior:
- The Process is polymorphic and can change its structure
- Creates a Toolbar Extension for Internet Explorer
- Adds new menu items in the Internet Explorer Right Click menu
- Changes the Internet Explorer Search Page
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Executes a Process
- Registers a Dynamic Link Library File
- Creates new folders on the system
CTBR(1).DLL has been the subject of the following behavior:
- Created as a process on disk
- Enabled as an In Process Object/Server - Common with DLL Injections
- Created and Registered as a Browser Helper Object in Internet Explorer
- Created as a Toolbar Extension for Internet Explorer
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Executed as a Process
Country Of Origin
The filename CTBR(1).DLL was first seen on May 27 2007 in the following geographical regions of the Webroot community:
- The United States on May 27 2007
- The United Kingdom on May 27 2007
- Japan on Sep 1 2007
- on Oct 15 2007
- Russian Federation on Oct 15 2007
- Spain on Dec 19 2007
- Europe on Mar 4 2008
File Name Aliases
CTBR(1).DLL can also use the following file names:
- CTBR.DLL
- BACKUP-20070912-130958-981.DLL
- BACKUP-20070519-183321-818.DLL
- CTBR.DLL
- IS-ETOP7.TMP
- 0B
Filesizes
The following file size has been seen:
- 1,122,816 bytes
- 1,219,832 bytes
- 1,133,568 bytes
- 1,152,000 bytes
- 879,616 bytes
- 1,112,576 bytes
- 1,245,432 bytes
File Type
The filename CTBR(1).DLL refers to many versions of a dynamic link library.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.