Threat Search: 

ThreatExpert's Statistics for Backdoor.VB!sd6 [PC Tools]:

Backdoor.VB!sd6 [PC Tools] is also known as:
Threat AliasNumber of Incidents
Backdoor.Trojan [Symantec]141
Generic BackDoor [McAfee]125
Backdoor.Win32.VB [Ikarus]120
Backdoor.Win32.VB.fdi [Kaspersky Lab]63
Mal/Generic-A [Sophos]41
W32/AutoRun-XU [Sophos]36
Backdoor.Win32.VB.frn [Kaspersky Lab]24
Trojan Horse [Symantec]24
Win-Trojan/Xema.variant [AhnLab]24
Generic.dx [McAfee]20
Backdoor.Win32.VB.gsx [Kaspersky Lab]18
Backdoor.Win32.VB.hkf [Kaspersky Lab]18
Backdoor.Win32.VB.fbh [Kaspersky Lab]16
Win32.SuspectCrc [Ikarus]12
Backdoor.VB.GEN [PC Tools]7
Backdoor.Win32.Rbot [Ikarus]6
Backdoor.Win32.VB.gjm [Kaspersky Lab]6
Backdoor.Win32.VB.gqs [Kaspersky Lab]6
Trojan:Win32/Malagent [Microsoft]6
Trojan:Win32/Meredrop [Microsoft]6
Backdoor.Win32.VB.ggs [Kaspersky Lab]5
Backdoor.Win32.VB.grp [Kaspersky Lab]5
PWS-Banker [McAfee]5
Trojan:Win32/Provis!rts [Microsoft]5
Backdoor.Win32.VB.dax [Kaspersky Lab]4
Backdoor.Win32.VB.hmq [Kaspersky Lab]4
Mal/Behav-109 [Sophos]4
Mal/Emogen-F [Sophos]4
Trojan.Crypt [Ikarus]4
Trojan:Win32/Sibleep.gen [Microsoft]4
Backdoor.Win32.VB.dcw [Kaspersky Lab]3
Backdoor.Win32.VB.fno [Kaspersky Lab]3
Backdoor.Win32.VB.gjo [Kaspersky Lab]2
Backdoor.Win32.VB.gkv [Kaspersky Lab]2
Backdoor.Win32.VB.gqz [Kaspersky Lab]2
Backdoor.Win32.VB.hmu [Kaspersky Lab]2
Backdoor.Win32.VB.hzm [Kaspersky Lab]2
Backdoor:Win32/VB [Microsoft]2
BKDR_VB.AEY [Trend Micro]2
Generic PUP.a [McAfee]2
Trojan.Win32.Agent2 [Ikarus]2
Trojan:Win32/Comronki!rts [Microsoft]2
W32.SillyDC [Symantec]2
Backdoor.Win32.Omega.a [Ikarus]1
Backdoor.Win32.SdBot [Ikarus]1
Backdoor.Win32.VB.aey [Kaspersky Lab]1
Backdoor.Win32.VB.gby [Kaspersky Lab]1
Backdoor.Win32.VB.gom [Kaspersky Lab]1
Backdoor.Win32.VB.gtf [Kaspersky Lab]1
Backdoor.Win32.VB.hhs [Kaspersky Lab]1
Backdoor.Win32.VB.hvf [Kaspersky Lab]1
Backdoor.Win32.VB.iju [Kaspersky Lab]1
Backdoor.Win32.VB.jy [Kaspersky Lab]1
BackDoor-DSS.dr [McAfee]1
Gen.Trojan [Ikarus]1
Generic VB.b [McAfee]1
Mal/Behav-043 [Sophos]1
Mal/Behav-160 [Sophos]1
Mal/Behav-160, Mal/Emogen-E [Sophos]1
Mal/Behav-210, Mal/Behav-160, Mal/Emogen-H, Mal/Emogen-F [Sophos]1
Mal/Emogen-G, Mal/Heuri-E [Sophos]1
Mal/Heuri-E, Mal/Emogen-G [Sophos]1
Mal/PWS-Fam [Sophos]1
Troj/Gom-Gen [Sophos]1
Troj/VB-EBX [Sophos]1
TROJ_DLOADER.OZ [Trend Micro]1
Trojan.Dropper [Symantec]1
Trojan:Win32/VB.HP [Microsoft]1
Trojan-Downloader.Win32.Agent.aiso [Kaspersky Lab]1
TrojanDropper:Win32/VB.FD [Microsoft]1
Trojan-Spy.Win32.Bancos.alh [Ikarus]1
VB-BackDoor.a.gen [McAfee]1
VirTool.Win32.VBInject [Ikarus]1
VirTool:Win32/VBInject.gen!U [Microsoft]1
W32/Autorun.worm.h [McAfee]1
W32/Koohey-Gen [Sophos]1
Win-Trojan/Agent.42341 [AhnLab]1
Win-Trojan/Icepoint.12288 [AhnLab]1
Worm.Win32.VB.zw [Kaspersky Lab]1
Worm:Win32/Autorun.MA [Microsoft]1
WORM_VB.HAV [Trend Micro]1

Backdoor.VB!sd6 [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
China15
Iran2
Russian Federation2
Spain2
Turkey1

Backdoor.VB!sd6 [PC Tools] is known to be created as:
%AppData%\svchost32.exe
%Profiles%\photo\photo1.exe
%ProgramFiles%\cinvig\inwinwn.exe
%Programs%\startup\lsass.exe
%System%\_svchost32.exe
%System%\explore.exe
%System%\mldmm.exe
%System%\rpc.exe
%Temp%\freezerlive.exe
%Temp%\ixp000.tmp\explore.exe
%Temp%\rundlll.exe
%Windir%\asedf2g2.exe
%Windir%\asifucan.exe
%Windir%\cursors\lsass.exe
%Windir%\igfxext.exe
%Windir%\important.htm.scr
%Windir%\important.mp3.com
%Windir%\important.mp3.scr
%Windir%\info.exe
%Windir%\info.scr
%Windir%\ipdriver.exe
%Windir%\jhil8.exe
%Windir%\msinet32.exe
%Windir%\notice.com
%Windir%\notice.mp2.com
%Windir%\notice.mp3.com
%Windir%\svshost.exe
%Windir%\sxfdwe4h.exe
%Windir%\winlogon.exe
%Windir%\ztescd32.exe
c:\bootsystem.exe
c:\directory\system.exe
c:\recycler\drive.exe
c:\sexgirls.exe
c:\vmpfull_tencent.com
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.