Threat Search: 

ThreatExpert's Statistics for Hacktool [Symantec]:

Hacktool [Symantec] is also known as:
Threat AliasNumber of Incidents
not-a-virus:NetTool.Win32.Agent.b [Kaspersky Lab]155,630
Trojan:Win32/Pepatch.E [Microsoft]144,992
Trojan-Downloader.Agent.AEN [PC Tools]120,170
BackDoor-AWQ [McAfee]94,958
Mal/Packer, Mal/EncPk-AI [Sophos]77,224
Mal/EncPk-AI [Sophos]68,950
Generic Malware.bc [McAfee]43,340
Trojan-Dropper.Agent [Ikarus]42,349
Mal_MLWR-5 [Trend Micro]40,582
Generic.dx [McAfee]36,900
Exploit.Win32.IMG-WMF.fk [Kaspersky Lab]36,675
Troj/PWS-AXY [Sophos]28,036
Exploit.Win32.IMG-WMF [Ikarus]23,472
Virus.Win32.Virtualizer [Ikarus]22,458
Exploit.IMG-WMF!sd6 [PC Tools]19,397
not-a-virus:PSWTool.Win32.MailPassView.as [Kaspersky Lab]17,693
Exploit.IMG-WMF [PC Tools]16,952
Rootkit.DR.CryptPack.A [PC Tools]16,770
Generic PWS.y!q [McAfee]16,640
Generic Dropper.ex [McAfee]14,904
not-a-virus:PSWTool.Win32.Messen [Ikarus]14,898
Win-Trojan/ExploitTool.3740 [AhnLab]12,877
Trojan.Win32.KillAV.ne [Kaspersky Lab]12,870
Troj/RkSal-A [Sophos]11,830
Packed.Generic.181 [Symantec]11,573
Worm:WinNT/Sality.AH!sys [Microsoft]11,570
not-a-virus:NetTool.Win32.Agent.b [Ikarus]10,638
Trojan.Zlob [Ikarus]10,595
NTRootKit-AB [McAfee]10,014
PSWTool.MailPassView!sd6 [PC Tools]8,648
Backdoor.Win32.Popwin [Ikarus]7,486
Trojan.Win32.KillAV [Ikarus]6,890
ProcKill-EC [McAfee]6,760
HackTool:Win32/Mailpassview [Microsoft]6,500
TROJ_KILLAV.GN [Trend Micro]6,110
Win-Trojan/AVKill.5077 [AhnLab]5,590
Mal/Generic-A [Sophos]4,890
Trojan-PWS.Win32.Maran [Ikarus]4,728
not-a-virus:NetTool.Win32.Agent [Ikarus]4,334
Win-Trojan/HackTool.13531 [AhnLab]3,940
PWSTool.MailPassView!sd6 [PC Tools]2,244
Generic PUP.x [McAfee]2,068
Mal/EncPk-AI, Mal/Packer [Sophos]1,970
TROJ_NSPM.RD [Trend Micro]1,576
Trojan-Spy.Banker.GEN [PC Tools]1,560
Trojan.Win32.KillAV.ne [Ikarus]1,430
Backdoor.Win32.Popwin.beg [Ikarus]1,182
Packed/NSPack [PC Tools]1,182
Win-Trojan/Xema.variant [AhnLab]1,147
not-a-virus:PSWTool.Win32.NetPass.et [Kaspersky Lab]992
Exploit.Win32.IMG-WMF.ex [Kaspersky Lab]978
Virus.Win32.Sality [Ikarus]915
Tool:Win32/IEPassRecover.A [Microsoft]841
Trojan.StartPage.AKF [PC Tools]815
PSWTool.NetPass!sd6 [PC Tools]698
not-a-virus:PSWTool.Win32.NetPass [Ikarus]652
not-a-virus:PSWTool.Win32.NetPass.q [Kaspersky Lab]484
HackTool.Win32.Homac [Kaspersky Lab]476
HackTool.Homac!sd5 [PC Tools]401
not-a-virus:PSWTool.Win32.NetPass.b [Ikarus]396
not-a-virus:PSWTool.Win32.MailPassView.ae [Kaspersky Lab]380
not-a-virus:PSWTool.Win32.FirePass.af [Kaspersky Lab]378
PSWTool.NetPass!sd5 [PC Tools]374
PSWTool.FirePass!sd6 [PC Tools]344
not-a-virus:PSWTool.Win32.PasswordFox [Ikarus]342
Generic PWS.y [McAfee]331
HackTool:Win32/Homac.A [Microsoft]330
Mal/Packer [Sophos]311
HackTool.Win32.Homac [Ikarus]289
HackTool.Agent!sd5 [PC Tools]256
Hacktool.Generic [PC Tools]256
Win-Trojan/HackTool.7200 [AhnLab]242
Virus.Win32.Trojan [Ikarus]235
not-a-virus:PSWTool.Win32.NetPass.et [Ikarus]232
HackTool.Win32.Agent.eh [Kaspersky Lab]224
not-a-virus:PSWTool.Win32.NetPass.eg [Kaspersky Lab]220
TSPY_ONLINE.BRU [Trend Micro]196
PWSTool.NetPass!sd6 [PC Tools]188
HackTool.Win32.Agent [Ikarus]178
Generic PUP.b [McAfee]173
Trojan-PSW.OnLineGames!sd5 [PC Tools]162
Troj/Xarp-A [Sophos]137
Win-Trojan/ARPSpoof.20480 [AhnLab]128
not-a-virus:PSWTool.Win32.NetPass.jd [Kaspersky Lab]126
Trojan-PSW.Win32.OnLineGames.xkv [Kaspersky Lab]84
Generic PUP.z [McAfee]80
not-a-virus:PSWTool.Win32.NetPass.fv [Kaspersky Lab]78
PSWTool.RAS!sd5 [PC Tools]70
Mal/Heuri-D [Sophos]66
not-a-Virus.Keygen.Adobe [Ikarus]66
not-a-virus:PSWTool.Win32.NetPass.ju [Kaspersky Lab]64
not-a-virus:PSWTool.Win32.FirePass.a [Kaspersky Lab]63
not-a-virus:PSWTool.Win32.NetPass.jj [Kaspersky Lab]63
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab]56
not-a-virus:PSWTool.Win32.SnadBoy.2011 [Kaspersky Lab]56
not-a-virus:PSWTool.Win32.RAS.a [Kaspersky Lab]52
Generic PWS.y!zy [McAfee]49
Generic PWS.y!za [McAfee]48
HackTool:Win32/Passview [Microsoft]48
not-a-virus:PSWTool.Win32.IEPassView.ar [Kaspersky Lab]48

Hacktool [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
Israel257
China79
Germany73
France45
Russian Federation35
United Kingdom13
Spain11
Italy10
Brazil7
Portugal5
Sweden3
Iran2
Netherlands2
Switzerland2
Taiwan2
Australia1
Egypt1
Hong Kong1
Oman1
Republic of Korea1
Turkey1
Viet Nam1

Hacktool [Symantec] is known to be created as:
%AppData%\databak3.exe
%AppData%\wintask3.exe
%DownloadedProgramFiles%\alg.exe
%DownloadedProgramFiles%\explorer.exe
%DownloadedProgramFiles%\spoolv.exe
%DownloadedProgramFiles%\svchost.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\fmpcv102\mpc\fmpc01.exe
%ProgramFiles%\fmpcv102\mpc\fmpc02.exe
%ProgramFiles%\fmpcv102\mpc\fmpc03.exe
%ProgramFiles%\fmpcv102\mpc\fmpc04.exe
%ProgramFiles%\fmpcv102\mpc\fmpc05.exe
%ProgramFiles%\fmpcv102\mpc\fmpc06.exe
%ProgramFiles%\fmpcv102\mpc\fmpc07.exe
%ProgramFiles%\fmpcv102\mpc\fmpc08.exe
%ProgramFiles%\fmpcv102\mpc\fmpc09.exe
%ProgramFiles%\fmpcv102\mpc\fmpc10.exe
%ProgramFiles%\fmpcv102\mpc\fmpc11.exe
%ProgramFiles%\fmpcv102\mpc\fmpc12.exe
%ProgramFiles%\fmpcv102\mpc\fmpc13.exe
%ProgramFiles%\fmpcv102\mpc\fmpc14.exe
%ProgramFiles%\fmpcv102\mpc\fmpc15.exe
%ProgramFiles%\fmpcv102\mpc\fmpc16.exe
%ProgramFiles%\fmpcv102\mpc\fmpc17.exe
%ProgramFiles%\fmpcv102\mpc\fmpc18.exe
%ProgramFiles%\fmpcv102\mpc\fmpc19.exe
%ProgramFiles%\fmpcv102\mpc\fmpc20.exe
%ProgramFiles%\ie passview\iepv.exe
%ProgramFiles%\internet explorer\keygen.exe
%ProgramFiles%\mail passview\mailpv.exe
%ProgramFiles%\msn\msn.exe
%ProgramFiles%\network password recovery\netpass.exe
%ProgramFiles%\nirsoft\password recovery package\astlog.exe
%ProgramFiles%\nirsoft\password recovery package\iepv.exe
%ProgramFiles%\nirsoft\password recovery package\mailpv.exe
%ProgramFiles%\nirsoft\password recovery package\netpass.exe
%ProgramFiles%\nirsoft\password recovery package\passwordfox.exe
%ProgramFiles%\nirsoft\password recovery package\rdpv.exe
%ProgramFiles%\nirsoft\password recovery package\sniffpass.exe
%ProgramFiles%\outlook express\keygen.exe
%ProgramFiles%\pc auto shutdown\autoshutdown.exe
%ProgramFiles%\pstpassword\pstpassword.exe
%ProgramFiles%\shoppingdum\shoppingdumdll.dll
%ProgramFiles%\winrar\original_files_and_patch\keygen.exe
%ProgramFiles%\xsharez scanner 3\xsharez_d.exe
%ProgramFiles%\zero freezer 1.5\data_file.exe
%System%\360box.exe
%System%\360tay.exe
%System%\360trac.exe
%System%\360traf.exe
%System%\360trag.exe
%System%\360traj.exe
%System%\360trak.exe
%System%\360trav.exe
%System%\360trax.exe
%System%\36osafe.exe
%System%\36otray.exe
%System%\a1g.exe
%System%\ads\mailpv.dll
%System%\antiwpa.dll
%System%\arp.com
%System%\bifrost\server.exe
%System%\button.dll
%System%\catroot2\wwwupdate.exe
%System%\chdk.exe
%System%\chdskk.exe
%System%\dk\calling.com
%System%\dkdk.exe
%System%\dnserv.dll
%System%\drivers\alg.exe
%System%\drivers\clandt.sys
%System%\drivers\comint32.sys
%System%\drivers\copkyyc32.sys
%System%\drivers\enjnpl.sys
%System%\drivers\fjdkin.sys
%System%\drivers\fjjgon.sys
%System%\drivers\fjljkn.sys
%System%\drivers\fjnjrn.sys
%System%\drivers\fjsmnn.sys
%System%\drivers\fkljon.sys
%System%\drivers\fkomsn.sys
%System%\drivers\fldlrn.sys
%System%\drivers\flgmsn.sys
%System%\drivers\flkpmn.sys
%System%\drivers\flsno.sys
%System%\drivers\fmplfn.sys
%System%\drivers\fnlnkn.sys
%System%\drivers\fnnkqn.sys
%System%\drivers\fnnqmn.sys
%System%\drivers\fnpggn.sys
%System%\drivers\fnpkrn.sys
%System%\drivers\fnpnm.sys
%System%\drivers\fnskrn.sys
%System%\drivers\fnsnkn.sys
%System%\drivers\fohnpn.sys
%System%\drivers\fokijn.sys
%System%\drivers\fomts.sys
%System%\drivers\fonqnn.sys
%System%\drivers\fooknn.sys
%System%\drivers\foonln.sys
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %DownloadedProgramFiles% is a variable that refers to the file system directory containing downloaded program files. A typical path is C:\Windows\Downloaded Program Files.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).