Threat Search: 

ThreatExpert's Statistics for BackDoor-DVR [McAfee]:

BackDoor-DVR [McAfee] is also known as:
Threat AliasNumber of Incidents
Win32/IRCBot.worm.variant [AhnLab]385
Backdoor.Win32.IRCBot.jvw [Kaspersky Lab]371
VirTool:Win32/CeeInject.gen!R [Microsoft]283
Backdoor.Win32.IRCBot [Ikarus]282
Mal/Inject-M [Sophos]277
Backdoor.Trojan [Symantec]231
Backdoor.IRCBot!sd6 [PC Tools]189
Mal/Bckdr-C, Mal/Inject-M [Sophos]103
Backdoor.IRC.Bot [Symantec]89
Backdoor:Win32/Agent [Microsoft]77
Virus.Win32.Injector [Ikarus]58
Trojan Horse [Symantec]45
Backdoor.Win32.IRCBot.irl [Kaspersky Lab]44
VirTool:Win32/CeeInject.B [Microsoft]34
Backdoor.IRC!sd6 [PC Tools]26
Mal/UnkPack-Fam [Sophos]24
Backdoor.IRC [PC Tools]23
Trojan:Win32/Meredrop [Microsoft]9
Trojan.Generic [PC Tools]5
Trojan:Win32/Inject.AA [Microsoft]5
Backdoor:Win32/Bifrose.AE [Microsoft]4
Mal/Generic-A, Mal/Bckdr-C, Mal/Inject-M [Sophos]4
Backdoor.Trojan [PC Tools]3
Backdoor.Bifrose [Symantec]2
Mal/Bckdr-C [Sophos]2
Mal/Bckdr-C, Mal/Inject-M, Mal/Behav-103, Mal/Behav-043 [Sophos]2
Mal/Inject-M, Mal/Behav-103 [Sophos]2
Mal/Inject-M, Mal/Behav-103, Mal/Behav-043 [Sophos]2
Troj/Agent-LCN [Sophos]2
Trojan.Meredrop [Ikarus]2
Win-Trojan/Agent.62845.C [AhnLab]2
Backdoor.Bifrose [PC Tools]1
Backdoor.Win32.Agent.agbb [Kaspersky Lab]1
Backdoor.Win32.IRCBot.img [Kaspersky Lab]1
Backdoor.Win32.IRCBot.imu [Kaspersky Lab]1
Backdoor.Win32.Poison.zlm [Kaspersky Lab]1
HeurEngine.MaliciousPacker [PC Tools]1
Mal/Bckdr-C, Mal/Inject-M, Mal/Bckdr-C, Mal/Inject-M [Sophos]1
Mal/Behav-103 [Sophos]1
Mal/Generic-A [Sophos]1
Mal/Inject-M, Mal/Behav-043 [Sophos]1
Mal/Krap-K, Mal/Krap-K [Sophos]1
Packed.Generic.187 [Symantec]1
Troj/Poison-AV [Sophos]1
Trojan.Win32.Buzus.bllj [Kaspersky Lab]1
Trojan.Win32.Refroso [Ikarus]1
Trojan.Win32.Refroso.asdv [Kaspersky Lab]1
Trojan.Win32.Refroso.egi [Kaspersky Lab]1
VirTool:Win32/Runcrypt.E [Microsoft]1
W32.HLLP.Sality.O [Symantec]1
Win-Trojan/Poison.40491 [AhnLab]1

BackDoor-DVR [McAfee] is known to be created as:
%AppData%\bifrost\server.exe
%Profiles%\no_love_6.exe
%ProgramFiles%\0pdate\ups.exe
%ProgramFiles%\aey\playeur.exe
%ProgramFiles%\bifrost\asd.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\win.exe
%ProgramFiles%\burn\run.exe
%ProgramFiles%\cc\server.exe
%ProgramFiles%\coffin\server.exe
%ProgramFiles%\ctf32\ctf32.exe
%ProgramFiles%\defa\defat.exe
%ProgramFiles%\lssas\lssas.exe
%ProgramFiles%\m.scr
%ProgramFiles%\microsoft\experience.exe
%ProgramFiles%\msn\msnmsngr.exe
%ProgramFiles%\system32\system32.exe
%ProgramFiles%\system-second\home.exe
%ProgramFiles%\update\update.exe
%ProgramFiles%\utorent\windows.exe
%ProgramFiles%\windows nt\htrn_jis.exe
%Programs%\startup\sexy.exe
%System%\1520gr6r1512.png.exe
%System%\3.exe
%System%\bifrost\bosh.exe
%System%\bifrost\install.exe
%System%\bifrost\ksa.exe
%System%\bifrost\saret.exe
%System%\bifrost\server.exe
%System%\bifrost\sestem.exe
%System%\cdinfo\cfz.exe
%System%\coffin.exe
%System%\coffin\coffin.exe
%System%\explorer\explorer.exe
%System%\exporer\exporer.exe
%System%\help\winrar.exe
%System%\msn\msn.exe
%System%\plugin.exe
%System%\rsfouad\gess.exe
%System%\server.exe
%System%\serverc.exe
%System%\solo.exe
%System%\system\system.exe
%System%\system\wingrad.exe
%System%\system32\svchost.exe
%System%\windows\server.exe
%System%\windowsdll\windows.exe
%Temp%\1.exe
%Temp%\coffin.exe
%Temp%\decrypted.exe
%Temp%\ixp000.tmp\13.exe
%Temp%\ixp000.tmp\coffin.exe
%Temp%\obadah.exe
%Temp%\plugin.exe
%Temp%\server.exe
%Templates%\vvvv.exe
%Windir%\bifrost\server.exe
%Windir%\ctfmon\ctfmon2.exe
%Windir%\run\server.exe
c:\4.exe
c:\extracted\server1.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Templates% is a variable that refers to the file system directory that serves as a common repository for document templates. A typical path is C:\Documents and Settings\[UserName]\Templates.
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.