Threat Search: 

ThreatExpert's Statistics for DNSChanger.gen [McAfee]:

DNSChanger.gen [McAfee] is also known as:
Threat AliasNumber of Incidents
Trojan:Win32/Alureon.gen!J [Microsoft]6,196
Trojan.Win32.Agent.akwc [Kaspersky Lab]5,256
Trojan Horse [Symantec]5,174
Mal/AdvPatch-A, Mal/Broute-A [Sophos]5,042
Worm.AutoRun.GEN [PC Tools]2,737
Trojan.Win32.Agent [Ikarus]2,670
Trojan.Win32.Alureon.J [Ikarus]2,570
Trojan:Win32/Alureon.BB [Microsoft]1,406
Trojan.Alureon.J [PC Tools]1,224
Troj/VcRtHack-A [Sophos]830
Trojan.Win32.Alureon [Ikarus]785
Backdoor.Tidserv!inf [Symantec]753
Backdoor.Tidserv!sd6 [PC Tools]534
Mal/Generic-A [Sophos]103
Trojan:Win32/Alureon.gen [Microsoft]99
Trojan:Win32/Alureon.gen!N [Microsoft]67
Rootkit.Win32.Agent.dqy [Kaspersky Lab]64
Backdoor.Tidserv [Symantec]53
Trojan.TDss.1 [Ikarus]36
Trojan.Zlob [Symantec]35
Packed.Generic.200 [Symantec]32
Trojan:WinNT/Alureon.C [Microsoft]32
Mal/EncPk-EQ [Sophos]26
Trojan-Downloader.Win32.Renos.AQ [Ikarus]26
Mal/EncPk-GB [Sophos]25
Mal/TDSS-A [Sophos]25
Rootkit.Win32.Agent [Ikarus]25
Rootkit.Win32.TDSS [Ikarus]25
Trojan.Win32.Patched [Ikarus]25
Trojan.Win32.Patched.fl [Kaspersky Lab]25
Trojan:Win32/Alureon.BI [Microsoft]25
Win-Trojan/Dnschanger.4278 [AhnLab]24
Win-Trojan/Xema.variant [AhnLab]24
Troj/MsvcrtHk-C [Sophos]23
Backdoor.Win32.UltimateDefender.gen [Kaspersky Lab]21
Trojan.TDSServ [PC Tools]20
Trojan.Vundo [Symantec]20
Trojan-Downloader.Win32.Small.aczp [Kaspersky Lab]20
Mal/EncPk-CZ [Sophos]19
Trojan.Fakeavalert [Symantec]17
Backdoor.Trojan [Symantec]16
Mal/Generic-A, Mal/TDSSPack-B [Sophos]16
Packed.Generic.188 [Symantec]15
PE_PATCHED.HT [Trend Micro]15
Trojan.Patched!sd6 [PC Tools]15
Mal/TDSS-A, Mal/EncPk-CZ [Sophos]14
Trojan.Flush.A [Symantec]13
Trojan-Downloader.Small!sd6 [PC Tools]12
Trojan.Win32.DNSChanger [Ikarus]11
Virus.Win32.Fabot [Ikarus]10
Trojan.DNSChanger.PW [PC Tools]9
Rootkit.Win32.TDSS.eyj [Kaspersky Lab]8
Troj/Meredrop-A [Sophos]8
Mal/TDSSPack-A [Sophos]7
Trojan.WinNT [Ikarus]7
Packed.Win32.Tdss.c [Kaspersky Lab]6
TROJ_ZLOB.CJG [Trend Micro]6
Trojan.Adclicker [Symantec]6
Trojan.DNSChanger!sd5 [PC Tools]6
Trojan.Flush.L [Symantec]6
Trojan.Win32.DNSChanger.io [Kaspersky Lab]6
Trojan.Win32.Pakes [Ikarus]6
Backdoor:Win32/Refpron.D [Microsoft]5
Hoax.Win32.Renos.ebd [Kaspersky Lab]5
Mal/Alureon-D [Sophos]5
Mal/BadNSIS [Sophos]5
Mal/EncPk-GU [Sophos]5
Trojan:Win32/Alureon.BJ [Microsoft]5
W32.SillyDC [Symantec]5
Bloodhound.Packed.7 [Symantec]4
Mal/Behav-321, Mal/TDSS-A [Sophos]4
Mal/RootKit-Fam [Sophos]4
Troj/Rootkit-DP [Sophos]4
TROJ_DNSCHANG.BM [Trend Micro]4
TROJ_IRCBOT.AUR [Trend Micro]4
TROJ_ZLOB.ALQ [Trend Micro]4
Trojan.DNSChanger [Ikarus]4
Trojan.Win32.DNSChanger.abk [Kaspersky Lab]4
Trojan.Win32.DNSChanger.vt [Kaspersky Lab]4
Trojan.Win32.Pakes.mzs [Kaspersky Lab]4
Trojan.Win32.Tdss [Ikarus]4
Trojan.Win32.TDSS.abiu [Kaspersky Lab]4
Trojan.Win32.TDSS.tzc [Kaspersky Lab]4
Trojan-Downloader.Win32.Small [Ikarus]4
W32.SillyIM [Symantec]4
W32.Stration@mm [Symantec]4
W32.Tidserv [Symantec]4
Hacktool.Rootkit [Symantec]3
Mal/Behav-196 [Sophos]3
Mal/EncPk-CO [Sophos]3
Mal/TDSS-B [Sophos]3
Troj/AdvHack-A [Sophos]3
Troj/FkAvDl-Fam [Sophos]3
Trojan.Packed.7 [Symantec]3
Trojan.Win32.Agent2 [Ikarus]3
Trojan:Win32/Alureon.AS [Microsoft]3
Trojan:Win32/Alureon.BL [Microsoft]3
Trojan:Win32/Alureon.gen!H [Microsoft]3
W32.SillyFDC [Symantec]3
Backdoor.Win32.TDSS [Ikarus]2

DNSChanger.gen [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China10
Russian Federation2
Spain1
Ukraine1

DNSChanger.gen [McAfee] is known to be created as:
%System%\cssrss.exe
%System%\dicotta.exe
%System%\dmdij.exe
%System%\dmjwm.exe
%System%\dmlzo.exe
%System%\dmpwk.exe
%System%\dmual.exe
%System%\dmvyw.exe
%System%\dmxtz.exe
%System%\dmyyp.exe
%System%\dmzoo.exe
%System%\drivers\dgmpqxt.sys
%System%\drivers\senekaalnbmnwu.sys
%System%\drivers\senekaapqjwxrb.sys
%System%\drivers\senekaepmtvpwb.sys
%System%\drivers\senekanquqxtoi.sys
%System%\drivers\senekawktevxiq.sys
%System%\jxi.exe
%System%\kdaam.exe
%System%\kdasp.exe
%System%\kdbmz.exe
%System%\kdcjq.exe
%System%\kdcqk.exe
%System%\kdcse.exe
%System%\kdcya.exe
%System%\kdddc.exe
%System%\kddgp.exe
%System%\kddji.exe
%System%\kddxs.exe
%System%\kddyf.exe
%System%\kdech.exe
%System%\kdeln.exe
%System%\kdenh.exe
%System%\kdeop.exe
%System%\kdfht.exe
%System%\kdfjr.exe
%System%\kdfkn.exe
%System%\kdfmj.exe
%System%\kdfnh.exe
%System%\kdfut.exe
%System%\kdfwd.exe
%System%\kdgvz.exe
%System%\kdgzy.exe
%System%\kdhmh.exe
%System%\kdhqk.exe
%System%\kdhsx.exe
%System%\kdidf.exe
%System%\kdiqc.exe
%System%\kdius.exe
%System%\kdjdx.exe
%System%\kdjlv.exe
%System%\kdjmu.exe
%System%\kdjoo.exe
%System%\kdkxu.exe
%System%\kdler.exe
%System%\kdleu.exe
%System%\kdlgg.exe
%System%\kdmbi.exe
%System%\kdmov.exe
%System%\kdmsx.exe
%System%\kdmwp.exe
%System%\kdmzw.exe
%System%\kdnhx.exe
%System%\kdnlf.exe
%System%\kdnxm.exe
%System%\kdodf.exe
%System%\kdonq.exe
%System%\kdowe.exe
%System%\kdozp.exe
%System%\kdpfr.exe
%System%\kdpoh.exe
%System%\kdppg.exe
%System%\kdpui.exe
%System%\kdpvv.exe
%System%\kdpyh.exe
%System%\kdqng.exe
%System%\kdqnt.exe
%System%\kdqrh.exe
%System%\kdqta.exe
%System%\kdrgz.exe
%System%\kdrpn.exe
%System%\kdryz.exe
%System%\kdsdp.exe
%System%\kdsjk.exe
%System%\kdslt.exe
%System%\kdsuj.exe
%System%\kdtov.exe
%System%\kdtvu.exe
%System%\kdufr.exe
%System%\kduns.exe
%System%\kdure.exe
%System%\kdvah.exe
%System%\kdvja.exe
%System%\kdwal.exe
%System%\kdwau.exe
%System%\kdwfk.exe
%System%\kdxau.exe
%System%\kdxbi.exe
%System%\kdxmc.exe
%System%\kdxpm.exe
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).