Threat Search: 

ThreatExpert's Statistics for Downloader.gen.a [McAfee]:

Downloader.gen.a [McAfee] is also known as:
Threat AliasNumber of Incidents
BKDR_CIADOOR.EA [Trend Micro]18,520
Backdoor.IRC.Bot [Symantec]18,289
Trojan.DL.VB.AAVI [PC Tools]17,900
Trojan-Downloader.Win32.VB.bsa [Kaspersky Lab]13,284
Downloader [Symantec]2,723
Adware.Maxifiles [PC Tools]2,029
Downloader.Trojan [Symantec]1,941
Generic.dx [McAfee]1,699
Trojan.DL.Winrean.A [PC Tools]1,671
Trojan Horse [Symantec]1,318
TROJ_DLOADER.PER [Trend Micro]1,218
Hacktool.Rootkit [Symantec]823
IRC.Backdoor.Trojan [Symantec]654
TROJ_DLOADER.FXN [Trend Micro]653
Mal/Generic-A [Sophos]559
Downloader-BJM [McAfee]546
Troj/Agent-GGQ [Sophos]546
Mal/Heuri-E, Mal/Emogen-N [Sophos]536
TrojanDownloader:Win32/VB [Microsoft]533
Infostealer.Gampass [Symantec]477
Trojan.Zlob [Symantec]470
Trojan-Downloader.Win32.Delf.epw [Kaspersky Lab]437
Trojan.Fakeavalert [Symantec]379
Trojan-Downloader.Small!sd6 [PC Tools]374
Trojan-Downloader.Win32.Small.hlp [Kaspersky Lab]360
Trojan-Downloader.VB!sd5 [PC Tools]325
TROJ_DLOADER.HE [Trend Micro]304
Trojan.DL.Small.AFWY [PC Tools]300
TROJ_SMALL.IEQ [Trend Micro]289
TrojanDownloader:Win32/Renos.DG [Microsoft]284
Trojan:Win32/Almanahe.D [Microsoft]280
TROJ_FRAUD.AB [Trend Micro]272
Troj/DwnLdr-HEO [Sophos]260
Virus.Win32.VB.FXE [Ikarus]254
TROJ_DLOADER.QQN [Trend Micro]252
Mal/FakeVir-E [Sophos]247
TROJ_ALMANAHE.AD [Trend Micro]220
Trojan.Fakeavalert!sd6 [PC Tools]218
TROJ_ZLOB.EXT [Trend Micro]217
Trojan-Downloader.Win32.VB.bzi [Kaspersky Lab]212
Trojan.Adclicker [Symantec]184
Trojan-Downloader.Win32.Homles.bz [Kaspersky Lab]174
Win-Trojan/Xema.variant [AhnLab]173
Trojan.Matcash.Gen [PC Tools]171
TROJ_VB.CEO [Trend Micro]162
Mal/Emogen-N, Mal/Heuri-E [Sophos]156
Trojan-Downloader.Small!sd5 [PC Tools]155
Trojan.Popuper [PC Tools]152
TrojanDownloader:Win32/Small.gen!Z [Microsoft]148
TROJ_DROPPER.UW [Trend Micro]147
Mal/Behav-156 [Sophos]146
TROJ_VB.AEA [Trend Micro]144
Trojan-Downloader.MisleadApp!sd5 [PC Tools]139
Trojan:WinNT/Bagle.gen [Microsoft]133
Trojan.Virantix.C [Symantec]132
Trojan.Vundo [Symantec]126
Downloader.MisleadApp [Symantec]125
TROJ_VIRANTIX.BF [Trend Micro]125
Mal/TibsPak, Mal/EncPk-BB [Sophos]123
Win-Trojan/Agent.6144.HK [AhnLab]122
Backdoor.Win32.Small.ejx [Kaspersky Lab]121
Trojan.Garntet [Symantec]121
Trojan.Win32.Agent.lom [Kaspersky Lab]121
Trojan-Downloader.Win32.Small [Ikarus]118
TrojanDownloader:Win32/Renos.gen!AQ [Microsoft]118
TROJ_DLOADR.CS [Trend Micro]117
Trojan-Downloader.Agent!sd5 [PC Tools]114
Mal/EncPk-CZ [Sophos]113
Hacktool.Rootkit!sd6 [PC Tools]112
Adware.UltimateDefend.C [PC Tools]110
WORM_DLOADER.RJL [Trend Micro]110
Backdoor.IRC!sd5 [PC Tools]107
Rootkit.Bagle.Gen.21 [PC Tools]105
Trojan-Spy.Gampass!sd6 [PC Tools]105
Trojan-Downloader.Win32.Small.eiv [Kaspersky Lab]100
Possible_Virus [Trend Micro]98
Trojan.FakeAlert [PC Tools]97
Trojan-Downloader.VB!sd6 [PC Tools]93
Trojan-Downloader.Win32.Adload.fu [Kaspersky Lab]92
TROJ_TINY.EQ [Trend Micro]90
Trojan.DL.VB.ACWT.Gen [PC Tools]85
Trojan-Downloader.Small.BUY [PC Tools]84
Trojan.KillAV!sd6 [PC Tools]81
Trojan-Downloader.Win32.Agent.gat [Kaspersky Lab]81
Trojan-Downloader.Win32.Small.hve [Kaspersky Lab]81
Trojan-Downloader.Win32.Adload.ma [Kaspersky Lab]80
Trojan-Downloader.Win32.Bagle.vj [Kaspersky Lab]80
Trojan.Win32.BHO.geh [Kaspersky Lab]78
TROJ_FAKEAVALE.L [Trend Micro]77
Trojan.KillAV [Symantec]77
Backdoor.Trojan [Symantec]75
Generic BackDoor.f [McAfee]74
Trojan-Dropper.Agent [Ikarus]73
TROJ_DLOADER.FP [Trend Micro]70
Trojan.Win32.BHO.eya [Kaspersky Lab]70
Troj/Virtum-Gen [Sophos]66
Trojan:Win32/Vundo.gen!H [Microsoft]66
Trojan-Downloader.Delf!sd5 [PC Tools]66
Trojan.Generic [Ikarus]65
PE_MUMAWOW.AU-O [Trend Micro]64

Downloader.gen.a [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Netherlands2,439
Ukraine2,026
China1,358
United Kingdom621
Slovenia271
Russian Federation243
Republic of Korea137
Brazil87
France25
Germany14
Taiwan12
Israel11
Italy11
Canada10
Spain6
Slovakia5
Sweden4
Argentina3
Australia3
Japan2
Thailand2
Turkey2
Belgium1
Greece1
Norway1
Poland1
Portugal1
Romania1
Saudi Arabia1
Singapore1

Downloader.gen.a [McAfee] is known to be created as:
%AllUsersProfile%\drm\drm.exe
%AllUsersProfile%\mydf080312.dll
%AllUsersProfile%\version.exe
%AppData%\adobe\rundtl.exe
%AppData%\cftmon.exe
%AppData%\hidires\flec003.exe
%AppData%\hidires\hidr.exe
%AppData%\icq\icqclient.exe
%AppData%\icq\rundll.exe
%AppData%\igouf.exe
%AppData%\key folder\filensys.exe
%AppData%\microsoft\dtsc\17120.exe
%AppData%\microsoft\dtsc\17529.exe
%AppData%\microsoft\dtsc\25394.exe
%AppData%\microsoft\dtsc\26619.exe
%AppData%\microsoft\windows\thcflht.exe
%AppData%\mjkpj.exe
%AppData%\pyqqm.exe
%AppData%\qycll.exe
%AppData%\shmqi.exe
%AppData%\spool.exe
%AppData%\vdmlz.exe
%AppData%\xszbe.exe
%AppData%\ytccs.exe
%CommonAppData%\fgtcpefi\tkvqdqzg.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\machinekeys.exe
%CommonAppData%\microsoft\crypto\rsa\rsa.exe
%CommonAppData%\microsoft\crypto\rsa\s-1-5-18\s-1-5-18.exe
%CommonAppData%\microsoft\microsoft.exe
%CommonAppData%\microsoft\network\connections\cm\cm.exe
%CommonAppData%\microsoft\network\connections\pbk\pbk.exe
%CommonPrograms%\accessories\accessibility\accessibility.exe
%CommonPrograms%\accessories\accessories.exe
%CommonPrograms%\accessories\communications\communications.exe
%CommonPrograms%\accessories\entertainment\entertainment.exe
%CommonPrograms%\programs.exe
%CommonPrograms%\startup\2.exe
%CommonPrograms%\startup\autorun.exe
%CommonPrograms%\startup\bios.exe
%CommonPrograms%\startup\ctfmen.exe
%CommonPrograms%\startup\kunbang.exe
%CommonPrograms%\startup\msnmsgr.exe
%CommonPrograms%\startup\msupd75437.exe
%CommonPrograms%\startup\startup.exe
%CommonPrograms%\startup\wallpaper.exe
%CommonPrograms%\startup\winsys3.exe
%CommonTemplates%\templates.exe
%DownloadedProgramFiles%\a1a2rc7b.dll
%DownloadedProgramFiles%\apy.dll
%DownloadedProgramFiles%\b7y.dll
%DownloadedProgramFiles%\bcy8h.dll
%DownloadedProgramFiles%\d846f.dll
%DownloadedProgramFiles%\el953n.dll
%DownloadedProgramFiles%\eu8c.dll
%DownloadedProgramFiles%\jig.dll
%DownloadedProgramFiles%\kpdqnuy.dll
%DownloadedProgramFiles%\mvmqth.dll
%DownloadedProgramFiles%\n8jt.dll
%DownloadedProgramFiles%\quqsifi.dll
%DownloadedProgramFiles%\rydx95bz.dll
%DownloadedProgramFiles%\sq8en7u.dll
%DownloadedProgramFiles%\x87dz.dll
%DownloadedProgramFiles%\xdtrlf7.dll
%DownloadedProgramFiles%\xvr.dll
%DownloadedProgramFiles%\ylmklc.dll
%DownloadedProgramFiles%\yos7mqrv.dll
%FontsDir%\00-11-22-33-44\system\wdfmgr.exe
%FontsDir%\b4b147bc522828731f1a016bfa72c073\system\svchost.exe
%FontsDir%\smct.exe
%FontsDir%\svchost.exe
%FontsDir%\svhost.exe
%FontsDir%\syn00-0c-29-ef-99-78\system\smss.exe
%FontsDir%\syn00-11-22-33-44\system\smss.exe
%Profiles%\default user\favorites\favorites.exe
%ProgramFiles%\123109.exe
%ProgramFiles%\138906.exe
%ProgramFiles%\154656.exe
%ProgramFiles%\170390.exe
%ProgramFiles%\186187.exe
%ProgramFiles%\201984.exe
%ProgramFiles%\adaptec\bin\v12\cdrv12.exe
%ProgramFiles%\advancedcleaner free\uadccw.exe
%ProgramFiles%\anonymous friend\exitaftoolbar.exe
%ProgramFiles%\antiviirus.exe
%ProgramFiles%\antivirus2008\antvrs.exe
%ProgramFiles%\c-media\bin\soundct.exe
%ProgramFiles%\common files\designer\wsock32.dll
%ProgramFiles%\common files\gretech\engine\v12\gretech12.exe
%ProgramFiles%\common files\gretech\engine\v13\gretech13.exe
%ProgramFiles%\common files\gretech\engine\v14\gretech14.exe
%ProgramFiles%\common files\lgt\engine\v12\hpctl12.exe
%ProgramFiles%\common files\mssoap\binaries\wsock32.dll
%ProgramFiles%\common files\mssoap\wsock32.dll
%ProgramFiles%\common files\odbc\data sources\wsock32.dll
%ProgramFiles%\common files\odbc\wsock32.dll
%ProgramFiles%\common files\services\svchost.exe
%ProgramFiles%\common files\services\wsock32.dll
%ProgramFiles%\common files\speechengines\microsoft\wsock32.dll
%ProgramFiles%\common files\speechengines\wsock32.dll
%ProgramFiles%\common files\svchost.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %CommonTemplates% is a variable that refers to the file system directory that contains the templates that are available to all users. A typical path is C:\Documents and Settings\All Users\Templates (Windows NT/2000/XP).
  • %DownloadedProgramFiles% is a variable that refers to the file system directory containing downloaded program files. A typical path is C:\Windows\Downloaded Program Files.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.