Threat Search: 

ThreatExpert's Statistics for BAT.Trojan.FormatCQ [Ikarus]:

BAT.Trojan.FormatCQ [Ikarus] is also known as:
Threat AliasNumber of Incidents
Mal/Generic-A [Sophos]25
Trojan Horse [Symantec]15
TrojanDropper:Win32/Agent.ASD [Microsoft]15
Win-Trojan/Xema.variant [AhnLab]11
Generic Dropper [McAfee]8
Generic Dropper!hv.h [McAfee]6
Generic.dx [McAfee]5
Trojan.Win32.Agent.ayfo [Kaspersky Lab]5
Trojan.Agent!sd6 [PC Tools]4
Trojan.BAT.Shutdown.af [Kaspersky Lab]4
Trojan-Dropper.Win32.BAT.ft [Kaspersky Lab]4
Virus.BAT.Agent.k [Kaspersky Lab]4
Win-Trojan/Agent.49152.YW [AhnLab]2
Win-Trojan/Agent.50176.FB [AhnLab]2
Win-Trojan/Agent.55808.CF [AhnLab]2
Win-Trojan/Agent.55808.CX [AhnLab]2
Win-Trojan/Shutdown.49152 [AhnLab]2
Generic.dx!ev [McAfee]1
Generic.dx!lp [McAfee]1
Generic.dx!y [McAfee]1
Troj/Bckdr-QTJ [Sophos]1
Trojan.BAT.Agent.ng [Kaspersky Lab]1
Trojan.BAT.Agent.nl [Kaspersky Lab]1
Trojan-Downloader.VBS.Small.l [Kaspersky Lab]1
Trojan-Dropper.Win32.BAT.ev [Kaspersky Lab]1
Trojan-Dropper.Win32.StartPage.k [Kaspersky Lab]1
TrojanDropper:Win32/Startpage.BA [Microsoft]1
W32.SillyFDC [Symantec]1
W32/Sybamed-A [Sophos]1

BAT.Trojan.FormatCQ [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
China1

BAT.Trojan.FormatCQ [Ikarus] is known to be created as:
%AppData%\noteinformation.exe
%MyDocuments%\10913.exe
%MyDocuments%\11250.exe
%MyDocuments%\batibot2.exe
%MyDocuments%\my music\10913.exe
%MyDocuments%\my music\11250.exe
%MyDocuments%\my music\batibot2.exe
%MyDocuments%\my pictures\10913.exe
%MyDocuments%\my pictures\11250.exe
%Programs%\startup\batibot.exe
%System%\10913.dll
%System%\10913.exe
%System%\11250.dll
%System%\11250.exe
%System%\3e947a0.exe
%System%\batibot.exe
%System%\drivers\usbinfo.com
%System%\screensave.scr
%Temp%\batibot.exe
%Temp%\batibot2.exe
%Temp%\ixp000.tmp\iexplorer.exe
%Temp%\kafan virlist 2009.04.07\090407-1-10.exe
%Temp%\kafan virlist 2009.04.07\090407-2-10.exe
%Temp%\kafan virlist 2009.04.07\090407-2-4.exe
%Temp%\kafan virlist 2009.04.07\090407-3-1.exe
%Temp%\kafan virlist 2009.04.07\090407-3-2.exe
%Temp%\kafan virlist 2009.04.07\090407-3-3.exe
%Temp%\kafan virlist 2009.04.16\090415-1-0.exe
%Temp%\rarsfx0\usbavowl\usbavowl\newscht.exe
%Temp%\rarsfx0\usbavowl\usbavowl\newseng.exe
%Windir%\batibot.exe
%Windir%\ssms.exe
c:\inetpub.exe
c:\recycler.exe
c:\windows.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %MyDocuments% is a variable that refers to the file system directory used to physically store a user's common repository of documents. A typical path is C:\Documents and Settings\[UserName]\My Documents.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.