Threat Search: 

ThreatExpert's Statistics for Backdoor [Ikarus]:

Backdoor [Ikarus] is also known as:
Threat AliasNumber of Incidents
Trojan Horse [Symantec]34
Mal/Generic-A [Sophos]33
Backdoor:Win32/Poison.Y [Microsoft]22
Troj/CDur-Gen [Sophos]21
Backdoor.Trojan [Symantec]19
BackDoor-AWQ.dll [McAfee]16
Backdoor:Win32/PcClient.ZL [Microsoft]14
Trojan.Generic [PC Tools]9
Trojan.Win32.Delf.ftn [Kaspersky Lab]9
Backdoor.Graybird [Symantec]8
Win-Trojan/Xema.variant [AhnLab]8
Generic.dx [McAfee]7
BackDoor-AWQ.b [McAfee]6
Generic BackDoor.t [McAfee]6
Mal/Behav-170, Mal/Whybo-A [Sophos]6
Mal/Behav-255, Mal/Behav-027 [Sophos]6
Mal/DelpDldr-B [Sophos]6
Generic PWS.y [McAfee]4
Generic.dx!fcw [McAfee]4
Generic.dx!wi [McAfee]4
not-a-virus:Server-Proxy.Win32.3proxy.dd [Kaspersky Lab]4
Troj/IMPWS-Gen [Sophos]4
Trojan.Win32.Delf.ffl [Kaspersky Lab]4
Win-Trojan/Backdoor.64000.B [AhnLab]4
Win-Trojan/Backdoor.64000.C [AhnLab]4
Backdoor.Trojan [PC Tools]3
BackDoor-CKB.gen.r [McAfee]3
Generic BackDoor!mz [McAfee]3
not-a-virus:Server-Proxy.Win32.3proxy [Ikarus]3
Trojan.Delf!sd6 [PC Tools]3
Trojan.Win32.CDur.di [Kaspersky Lab]3
Trojan.Win32.Delf.fja [Kaspersky Lab]3
Trojan:Win32/Bumat!rts [Microsoft]3
VirTool:Win32/DelfInject.gen!X [Microsoft]3
Backdoor.Ghostnet [Symantec]2
Generic BackDoor [McAfee]2
Generic.dx!mm [McAfee]2
Rootkit.Win32.Agent.hdb [Kaspersky Lab]2
Trojan.Delf [PC Tools]2
Trojan.Win32.Agent2.kps [Kaspersky Lab]2
TrojanSpy:Win32/Vwealer.H [Microsoft]2
Virus.Win32.Virut.ce [Kaspersky Lab]2
Virus:Win32/Virut.BM [Microsoft]2
W32.Virut.CF [Symantec]2
W32/Scribble-B [Sophos]2
Win32/Virut.F [AhnLab]2
Backdoor.Agent.rkf [PC Tools]1
Backdoor.Darkmoon [PC Tools]1
Backdoor.Darkmoon [Symantec]1
Backdoor.Delf.GEN [PC Tools]1
Backdoor.Win32.Agent.rkf [Kaspersky Lab]1
Backdoor.Win32.Agent.tng [Kaspersky Lab]1
Backdoor.Win32.Poison.abba [Kaspersky Lab]1
Backdoor:Win32/Delf.IW [Microsoft]1
Backdoor:Win32/PcClient.DT [Microsoft]1
Backdoor:Win32/Prosti.L [Microsoft]1
Backdoor:Win32/Venik.C [Microsoft]1
BackDoor-CKB.gen.q [McAfee]1
BackDoor-DUS [McAfee]1
BackDoor-EKJ [McAfee]1
Downloader.Trojan [Symantec]1
Generic Dropper [McAfee]1
Generic PUP.x [McAfee]1
Generic.dx!bgb [McAfee]1
Generic.dx!kkh [McAfee]1
Generic.dx!pz [McAfee]1
Mal/Behav-010 [Sophos]1
Mal/Behav-024, Mal/Emogen-Y [Sophos]1
Mal/Behav-255 [Sophos]1
Mal/Emogen-N [Sophos]1
Mal/Inet-Fam [Sophos]1
Mal/KoobHeur-A [Sophos]1
Mal/PWS-Fam [Sophos]1
Mal/SillyFDC-A [Sophos]1
New Win32 [McAfee]1
Packed.Win32.CPEX-based.ht [Kaspersky Lab]1
PE_SALITY.AZ [Trend Micro]1
PE_VIRUT.AP [Trend Micro]1
Rootkit.Agent [PC Tools]1
Rootkit.Agent!sd6 [PC Tools]1
Rootkit.Win32.Agent.epz [Kaspersky Lab]1
Rootkit.Win32.Agent.euy [Kaspersky Lab]1
Rootkit.Win32.Agent.fbi [Kaspersky Lab]1
Rootkit.Win32.Agent.gig [Kaspersky Lab]1
Rootkit.Win32.Agent.gll [Kaspersky Lab]1
Spyware.Screenspy [PC Tools]1
Spyware.Screenspy [Symantec]1
Troj/BDoor-ALC [Sophos]1
Troj/Bdoor-AOR [Sophos]1
TROJ_AQED.A [Trend Micro]1
Trojan.Farfli [PC Tools]1
Trojan.Farfli [Symantec]1
Trojan.KillAV [Symantec]1
Trojan.Win32.Agent.akmm [Kaspersky Lab]1
Trojan.Win32.Agent.cfnt [Kaspersky Lab]1
Trojan.Win32.Agent.cnfo [Kaspersky Lab]1
Trojan.Win32.Agent2 [Ikarus]1
Trojan.Win32.AntiAV.apn [Kaspersky Lab]1
Trojan.Win32.AntiAV.bix [Kaspersky Lab]1
Trojan.Win32.AntiAV.blw [Kaspersky Lab]1

Backdoor [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China17
Israel8
Turkey8
France2
Belgium1
Germany1
Netherlands1
Saudi Arabia1
Taiwan1
United Arab Emirates1

Backdoor [Ikarus] is known to be created as:
%AppData%\microsoft\windows\media\ntwsmd.dll
%ProgramFiles%\360saofe.exe
%ProgramFiles%\sfx\sfx.dll
%ProgramFiles%\vm60nxtd.dll
%System%\bits.dll
%System%\dllcache\mspmsnsv.dll
%System%\drivers\etc\aj5kc0ra.dll
%System%\drivers\etc\cjw08dps.dll
%System%\drivers\etc\fuort4sy.dll
%System%\drivers\etc\jpgx4nuc.dll
%System%\drivers\etc\kvcdwsfm.dll
%System%\drivers\etc\md1qjgla.dll
%System%\drivers\etc\nlcqsccj.dll
%System%\drivers\etc\po0bgqjw.dll
%System%\drivers\etc\shalvj3t.dll
%System%\drivers\etc\srlnub5p.dll
%System%\drivers\etc\ud3zixwb.dll
%System%\drivers\etc\uhu1igks.dll
%System%\drivers\etc\v7vhtbe6.dll
%System%\drivers\etc\xwruudsr.dll
%System%\drivers\etc\zilzq6uq.dll
%System%\drivers\tcpip4.sys
%System%\fywd.dll
%System%\kiudsxd.dll
%System%\kmunsld.dll
%System%\kuufspd.dll
%System%\mspmsnsvr.dll
%System%\nwcworkstation.dll
%System%\resesmgr.exe
%System%\rnmcttc.dll
%System%\rvmutnc.dll
%System%\rwmdtsc.dll
%System%\rzmgthc.dll
%System%\servergmh.dll
%System%\sjmytph.dll
%System%\systen.exe
%System%\tpmkths.dll
%System%\update.dll
%System%\wssvc7.dll
%Temp%\server.dll
c:\data.msi\cssrs.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).