Threat Search: 

ThreatExpert's Statistics for Backdoor:Win32/Refpron.gen!C [Microsoft]:

Backdoor:Win32/Refpron.gen!C [Microsoft] is also known as:
Threat AliasNumber of Incidents
Refpron.gen [McAfee]98
Backdoor.Win32.Refpron [Ikarus]59
Mal/Generic-A [Sophos]49
Packed.Win32.Koblu.b [Kaspersky Lab]26
Packed.Win32.Koblu [Ikarus]22
Mal/PWS-Fam [Sophos]17
Troj/Comsa-E [Sophos]17
Trojan.Win32.Koblu [Ikarus]17
Downloader [Symantec]16
Win-Trojan/Xema.variant [AhnLab]16
Refpron.gen.c [McAfee]14
Win-Trojan/Agent.212992.JS [AhnLab]13
W32/DelpBck-Gen [Sophos]10
Win-Trojan/Koblu.173568.F [AhnLab]10
Trojan.Win32.Delf.lpr [Kaspersky Lab]9
Trojan Horse [Symantec]7
SecurityRisk.Downldr [Symantec]5
Spyware.Screenspy [Symantec]5
Trojan.Win32.Delf.lbv [Kaspersky Lab]5
Trojan.Win32.Koblu.kg [Kaspersky Lab]5
Trojan.Win32.Koblu.aff [Kaspersky Lab]4
Trojan.Win32.Koblu.pr [Kaspersky Lab]4
Trojan-Downloader.Win32.Agent.bscm [Kaspersky Lab]4
Trojan-Downloader.Win32.DlfBfkg.ds [Kaspersky Lab]4
Trojan-Downloader.Win32.DlfBfkg.md [Kaspersky Lab]4
Win-Trojan/Koblu.98816.O [AhnLab]4
New Win32 [McAfee]3
Trojan.Refpron.GEN [PC Tools]3
W32.Virut.CF [Symantec]3
Generic BackDoor!dz [McAfee]2
Trojan.Win32.Delf.mqj [Kaspersky Lab]2
Trojan.Win32.Delf.mrd [Kaspersky Lab]2
Trojan.Win32.Kidozer.f [Kaspersky Lab]2
Trojan-Downloader.Win32.Delf.tlr [Kaspersky Lab]2
Trojan-Downloader.Win32.Delf.uhf [Kaspersky Lab]2
Trojan-Dropper.Win32.Agent.alvl [Kaspersky Lab]2
Win-Trojan/Koblu.174592.AA [AhnLab]2
Win-Trojan/Refpron.124928.F [AhnLab]2
Win-Trojan/Refpron.157696.E [AhnLab]2
Backdoor.Win32.Delf.ous [Kaspersky Lab]1
Dropper/Agent.174080.J [AhnLab]1
Generic BackDoor!ec [McAfee]1
Generic BackDoor!v [McAfee]1
Generic Downloader.x!gc [McAfee]1
Generic Downloader.x!hz [McAfee]1
Refpron.gen.g [McAfee]1
Rundis [McAfee]1
Troj/BDoor-AVP [Sophos]1
Troj/Refpron-H [Sophos]1
Trojan.Adclicker [Symantec]1
Trojan.Win32.Agent.cady [Kaspersky Lab]1
Trojan.Win32.Agent.cdao [Kaspersky Lab]1
Trojan.Win32.Agent2.hij [Kaspersky Lab]1
Trojan.Win32.Delf.mnb [Kaspersky Lab]1
Trojan.Win32.Delf.moc [Kaspersky Lab]1
Trojan.Win32.Delf.mou [Kaspersky Lab]1
Trojan.Win32.Delf.mre [Kaspersky Lab]1
Trojan.Win32.Koblu.abp [Kaspersky Lab]1
Trojan.Win32.Koblu.jh [Kaspersky Lab]1
Trojan.Win32.Koblu.lb [Kaspersky Lab]1
Trojan.Win32.Koblu.xs [Kaspersky Lab]1
Trojan.Win32.Koblu.zn [Kaspersky Lab]1
Trojan-Downloader.Agent.cgax [PC Tools]1
Trojan-Downloader.Win32.Agent.brdo [Kaspersky Lab]1
Trojan-Downloader.Win32.Agent.cgax [Kaspersky Lab]1
Trojan-Downloader.Win32.Delf.tka [Kaspersky Lab]1
Trojan-Downloader.Win32.Delf.ttv [Kaspersky Lab]1
Trojan-Downloader.Win32.Delf.ugr [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ajm [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.at [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ay [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ca [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.cf [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.dx [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.fe [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.gm [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.hc [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.kn [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ko [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ks [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.lp [Kaspersky Lab]1
Trojan-Downloader.Win32.DlfBfkg.ol [Kaspersky Lab]1
Virus.Win32.Virut.ce [Kaspersky Lab]1
W32/Scribble-B [Sophos]1
Win32/Virut.F [AhnLab]1
Win-Trojan/Agent.173568.W [AhnLab]1
Win-Trojan/Agent.212480.T [AhnLab]1
Win-Trojan/Agent2.212480.F [AhnLab]1
Win-Trojan/Koblu.156160.B [AhnLab]1
Win-Trojan/Koblu.226816 [AhnLab]1
Win-Trojan/Koblu.226816.C [AhnLab]1
Win-Trojan/Koblu.97792.G [AhnLab]1
Win-Trojan/Koblu.98816.E [AhnLab]1
Win-Trojan/Refpron.134656 [AhnLab]1
Win-Trojan/Refpron.157696 [AhnLab]1
Win-Trojan/Refpron.174592.E [AhnLab]1
Win-Trojan/Xema.123392 [AhnLab]1

Backdoor:Win32/Refpron.gen!C [Microsoft] has the following possible country of origin:
OriginNumber of Incidents
China213

Backdoor:Win32/Refpron.gen!C [Microsoft] is known to be created as:
%System%\afisicx.exe
%System%\mobsyn.exe
%System%\sopidkc.exe
%System%\tpsaxyd.exe
%System%\tpszxyd.sys
%System%\w.exe
%Temp%\090430-2-1.exe
%Temp%\090521-8-4.exe
%Temp%\090522-3-1.exe
%Temp%\090522-3-3.exe
%Temp%\090523-a-33.exe
%Temp%\090602-4-6.exe
%Temp%\090602-5-3.exe
%Temp%\090610-6-6.exe
%Temp%\090611-4-1.exe
%Temp%\090611-4-3.exe
%Temp%\090612-7-1.exe
%Temp%\090613-5-0.exe
%Temp%\090613-5-2.exe
%Temp%\090614-5-0.exe
%Temp%\090614-5-1.exe
%Temp%\090614-a-19.exe
%Temp%\090614-a-38.exe
%Temp%\090615-4-8.exe
%Temp%\090615-5-1.exe
%Temp%\090618-5-5.exe
%Temp%\090618-5-9.exe
%Temp%\kafan virlist 2009.05.31\090531-3-4.exe
%Temp%\kafan virlist 2009.05.31\090531-3-7.exe
%Temp%\kafan virlist 20090714\090714-6-5.exe
%Temp%\kafan virlist 20090715\090714-8-11.exe
%Temp%\kafan virlist 20090715\090714-9-1.exe
%Temp%\kafan virlist 20090715\090714-9-2.exe
%Temp%\kafan virlist 20090715\090714-9-3.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).