Threat Search: 

ThreatExpert's Statistics for Generic Rootkit.d [McAfee]:

Generic Rootkit.d [McAfee] is also known as:
Threat AliasNumber of Incidents
Hacktool.Rootkit [Symantec]28,802
Rootkit.Win32.Agent.ex [Kaspersky Lab]20,744
TrojanSpy:Win32/Ursnif [Microsoft]20,592
TROJ_ROOTKIT.FX [Trend Micro]19,734
Rootkit.Agent.EX [PC Tools]19,668
Troj/Rootkit-DK [Sophos]19,591
Rootkit.Win32.Agent.ex [Ikarus]16,704
Win-Trojan/Agent.8192.BP [AhnLab]6,864
Trojan-Proxy.Win32.Wopla.ag [Kaspersky Lab]3,528
Trojan-Proxy.Wopla [PC Tools]3,444
Rootkit.Agent!sd5 [PC Tools]2,780
Rootkit.Win32.Agent.jj [Kaspersky Lab]2,160
TROJ_WOPLA.CP [Trend Micro]1,722
TROJ_WOPLA.CR [Trend Micro]1,722
Generic.dx [McAfee]1,664
Troj/Rootkit-ES [Sophos]1,287
Hacktool.Rootkit!sd6 [PC Tools]1,284
TROJ_AGENT.ZNH [Trend Micro]1,272
Troj/NTRootK-CG [Sophos]1,224
Virus.Win32.Trojan [Ikarus]1,221
Rootkit.Win32.Agent [Ikarus]1,209
Trojan:Win32/Rootkit.J [Microsoft]1,200
Rootkit.Agent.CZBC [PC Tools]858
TROJ_TIBS.AP [Trend Micro]840
Packed.Win32.Tibs.ap [Kaspersky Lab]812
Infostealer.Snifula [Symantec]754
TROJ_AGENT.CWT [Trend Micro]667
TROJ_AGENT.ALDB [Trend Micro]575
Trojan-PWS.OnlineGames.ADRD [PC Tools]553
Win-Trojan/Rootkit.39936.C [AhnLab]495
Rootkit.Win32.Agent.sz [Kaspersky Lab]464
Win-Trojan/Agent.18944.DS [AhnLab]432
Adware:Win32/BHO.B [Microsoft]396
RTKT_AGENT.AFAC [Trend Micro]342
TROJ_AGENT.AEGL [Trend Micro]342
Rootkit.Win32.Agent.ajg [Kaspersky Lab]302
Mal/Generic-A [Sophos]299
Rootkit.Win32.Agent.md [Kaspersky Lab]228
Rootkit.Win32.Agent.me [Kaspersky Lab]228
VirTool:WinNT/Ursnif.A [Microsoft]174
Rootkit.Agent.WYU [PC Tools]171
Rootkit.Agent.WYV [PC Tools]171
Rootkit.Win32.Agent.nil [Kaspersky Lab]132
Trojan:WinNT/Killav.DK [Microsoft]121
Win-Trojan/Agent.3328.N [AhnLab]121
Win-Trojan/Agent.7680.CN [AhnLab]116
Troj/Agent-GXV [Sophos]100
Trojan:Win32/Rootkit.AFH [Microsoft]100
Trojan.WinNT [Ikarus]88
Troj/Proxy-HL [Sophos]84
Trojan-Proxy.Win32.Wopla.ag [Ikarus]84
Trojan-Proxy.Wopla!sd5 [PC Tools]84
Trojan.KillAV [PC Tools]77
Infostealer [Symantec]75
Trojan.KillAV.TE [PC Tools]75
Rootkit.Win32.Agent.jj [Ikarus]72
Hacktool.Rootkit!sd5 [PC Tools]64
Rootkit.Agent.GK [PC Tools]64
Virus.Win32.Sality [Ikarus]64
Virus.Win32.Sality.s [Kaspersky Lab]64
W32/Sality-AD [Sophos]64
VirTool:Win32/Rootkit.C [Microsoft]56
Win-Trojan/Sality.5477 [AhnLab]56
TROJ_AGENT.FZB [Trend Micro]48
TrojanProxy:Win32/Wopla.AG [Microsoft]42
TrojanProxy:Win32/Wopla.X [Microsoft]42
Win-Trojan/Wopla.30208 [AhnLab]42
Win-Trojan/Wopla.6962 [AhnLab]42
Troj/DwnLdr-GYV [Sophos]38
W32/Autorun-ABE [Sophos]35
Win-Trojan/Tcpz.170888 [AhnLab]35
VirTool:WinNT/Knockex.D [Microsoft]34
Trojan.Win32.Agent.kcr [Kaspersky Lab]32
Rootkit.Win32.Agent.iny [Kaspersky Lab]30
Rootkit.Agent!ct [PC Tools]29
Rootkit.Win32.Agent.ajg [Ikarus]25
Rootkit.Win32.Agent.btm [Kaspersky Lab]25
Trojan.Win32.StartPage.apb [Kaspersky Lab]25
Trojan-PWS.OnlineGames.AHRG [PC Tools]25
Troj/RootKit-CK [Sophos]24
Trojan:WinNT/Rootkitdrv [Microsoft]24
Adware.SuperUtilBar [PC Tools]20
Backdoor.Rootkit.W [Ikarus]20
Infostealer.Gampass [Symantec]20
TROJ_STARTPA.EGH [Trend Micro]20
TSPY_ONLINE.SJ [Trend Micro]20
VirTool:Win32/Rootkitdrv.DD [Microsoft]19
VirTool:WinNT/Rootkitdrv.EO [Microsoft]19
Rootkit.Win32.Agent.gvt [Kaspersky Lab]18
Virus.Win32.Rootkit [Ikarus]18
Trojan-Downloader.Agent.RLR [PC Tools]16
Trojan-GameThief.Win32.OnLineGames.sjsy [Kaspersky Lab]16
Spammer:WinNT/Srizbi.gen!B [Microsoft]15
TROJ_AGENT.TSP [Trend Micro]15
Trojan-PSW.Win32.OnLineGames.amoc [Kaspersky Lab]15
Trojan-PWS.Win32.OnLineGames [Ikarus]15
VirTool:WinNT/Fispids.gen!D [Microsoft]15
VirTool:WinNT/Siapag.gen!B [Microsoft]12
Mal/RootKit-Fam [Sophos]10
Mal/TinyDL-T [Sophos]10

Generic Rootkit.d [McAfee] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation33

Generic Rootkit.d [McAfee] is known to be created as:
%ProgramFiles%\drv\drv.sys
%System%\cabpck.dll
%System%\dllcache\beep.sys
%System%\dllcache\figaro.sys
%System%\drivers\2aff46d.sys
%System%\drivers\47f7ee35.sys
%System%\drivers\6ce3406e.sys
%System%\drivers\aybqcxy.sys
%System%\drivers\byoqpr.sys
%System%\drivers\bzjrrzzr.sys
%System%\drivers\bzpqcax.sys
%System%\drivers\fhhnln.sys
%System%\drivers\fihhkn.sys
%System%\drivers\fjmmmn.sys
%System%\drivers\fkgggn.sys
%System%\drivers\fkpnrn.sys
%System%\drivers\fllnln.sys
%System%\drivers\flpydiskk.sys
%System%\drivers\fmhpqn.sys
%System%\drivers\inljfn.sys
%System%\drivers\jrrzrrrr.sys
%System%\drivers\jwsrqtsr.sys
%System%\drivers\lyi33.sys
%System%\drivers\msosmsfpfis64.sys
%System%\drivers\msqmx.sys
%System%\drivers\ntosnh.sys
%System%\drivers\ntoss.sys
%System%\drivers\oybzpqc.sys
%System%\drivers\phy.sys
%System%\drivers\protect.sys
%System%\drivers\prxaybz.sys
%System%\drivers\ptk46.sys
%System%\drivers\ptvnptrr.sys
%System%\drivers\qtpprnuv.sys
%System%\drivers\quorslqy.sys
%System%\drivers\rdbsss.sys
%System%\drivers\rrrzjrjz.sys
%System%\drivers\sqsqstor.sys
%System%\drivers\stpsttnp.sys
%System%\drivers\streamm.sys
%System%\drivers\sttnsmur.sys
%System%\drivers\stuqtrno.sys
%System%\drivers\stwrulls.sys
%System%\drivers\symavc32.sys
%System%\drivers\sysdrv32.sys
%System%\drivers\t3qjqc.sys
%System%\drivers\tdii.sys
%System%\drivers\the_end.sys
%System%\drivers\uqsvntpo.sys
%System%\drivers\urroqrtq.sys
%System%\drivers\vsqqtmlx.sys
%System%\drivers\wmisvc.sys
%System%\drivers\xaybzpq.sys
%System%\drivers\xbyoqp.sys
%System%\drivers\yfxyrmscdxvuya.sys
%System%\drivers\zpqcaxb.sys
%System%\frmwrk.sys
%System%\gsbgqpwwfw.sys
%System%\ksys.sys
%System%\lanmandrv.sys
%System%\msmouse.sys
%System%\msobj.sys
%System%\mspk.sys
%System%\ntapldrv.sys
%System%\runtime.sys
%System%\swapm.sys
%System%\syssrv.sys
%Temp%\11252.sys
%Temp%\16061.sys
%Temp%\33486.sys
%Temp%\37750.sys
%Temp%\51455.sys
%Temp%\83101.sys
%Temp%\83611.sys
%Temp%\85544.sys
%Temp%\uq.dll
%Windir%\9129837.exe
%Windir%\new_drv.sys
%Windir%\widuxngq.sys
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.