Threat Search: 

ThreatExpert's Statistics for IRC-Worm.Win32.Tedeto.a [Ikarus]:

IRC-Worm.Win32.Tedeto.a [Ikarus] is also known as:
Threat AliasNumber of Incidents
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab]5,028
IRC/Client [McAfee]4,864
Backdoor.IRCBot [PC Tools]3,994
Win-Trojan/MircPack.1790464 [AhnLab]3,061
not-a-virus:Client-IRC.Win32.mIRC [Ikarus]2,952
IRC.Backdoor.Trojan [Symantec]233
Backdoor.mIRC [PC Tools]160
Trojan mIRC Client [McAfee]160
BrowserModifier:Win32/IGetNet [Microsoft]140
Troj/IRCFlood-T [Sophos]140
Virus.Win32.Parite.b [Kaspersky Lab]70
PE_PARITE.A [Trend Micro]68
W32.Pinfi [Symantec]68
W32/Pate.b [McAfee]68
Backdoor.IRC.Flood [PC Tools]48
TROJ_BOTIRC.A [Trend Micro]48
W32.IRCBot [Symantec]48
Virus.Parite.B [PC Tools]40
IRC/Flood.mirc [McAfee]36
Backdoor:Win32/IRCbot [Microsoft]32
Troj/Multidr-FT [Sophos]32
TROJ_INFECTED.AY [Trend Micro]28
Virus:Win32/Parite.B [Microsoft]24
W32/Parite-B [Sophos]24
BKDR_IRCBOT.BMF [Trend Micro]20
TROJ_IRCFLOOD.O [Trend Micro]20
Win-Trojan/MircPack.574464 [AhnLab]20
Win32/Parite [AhnLab]12
Mal/Zapchas-A [Sophos]8
Troj/Mirchack-L [Sophos]6
Virus.Win32.Drowor.a [Kaspersky Lab]6
W32.Mumawow.F!inf [Symantec]6
PE_CEKAR.B [Trend Micro]4
Troj/Banker-APQ [Sophos]4
Virus:Win32/Drowor.A [Microsoft]4
W32/Cekar.dam [McAfee]4
W32/Cekar-E [Sophos]4
Win32.Drowor.Gen [PC Tools]4
Backdoor.IRC.Zapchast [Kaspersky Lab]3
Backdoor.IRC.Zapchast [PC Tools]3
Trojan.mIRC-Based.AM [PC Tools]3
Backdoor.IRC.Zapchast.zwrc [Kaspersky Lab]2
Backdoor.Trojan [Symantec]2
BKDR_IRCFLOOD.AC [Trend Micro]2
Generic PUP.z [McAfee]2
IRC.Randon.M [PC Tools]2
IRC.Zapchast.AQ [PC Tools]2
Application.Ardamax_Keylogger [PC Tools]1
Backdoor.mIRC-Based.AB [PC Tools]1
Dropper/Zapchast.875652 [AhnLab]1
Generic Dropper!c [McAfee]1
Generic PUP.h [McAfee]1
IRC.Flood.CJ [PC Tools]1
IRC.Zapchast.AS [PC Tools]1
Mal/Generic-A [Sophos]1
Net-Worm.Win32.Randon.a [Kaspersky Lab]1
Renamed mIRC Client [McAfee]1
Troj/Zapchas-AX [Sophos]1
Trojan.DR.Duckirc.Gen [PC Tools]1

IRC-Worm.Win32.Tedeto.a [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation11
France1
Germany1

IRC-Worm.Win32.Tedeto.a [Ikarus] is known to be created as:
%ProgramFiles%\%systemdir%\system32.exe
%ProgramFiles%\%systemdir%\winasc.exe
%ProgramFiles%\dfdsfs\kiss.exe
%ProgramFiles%\fsdfs\kiss.exe
%ProgramFiles%\killsh\kiss.exe
%ProgramFiles%\kjhkjhjk\kiss.exe
%ProgramFiles%\mirc\mirc.exe
%ProgramFiles%\msngr\messenger.exe
%ProgramFiles%\sdfsdfs\kiss.exe
%System%\aicmirc.exe
%System%\bigslaps.exe
%System%\blablabla.exe
%System%\cache\spoolsvr.exe
%System%\caves.exe
%System%\coded.exe
%System%\directx\postcard\explorer.exe
%System%\dll\nvidia.exe
%System%\dllcache\svhost.exe
%System%\drivers\svchost.exe
%System%\explorer.exe
%System%\ka6ber.exe
%System%\karakirli.exe
%System%\kasber.exe
%System%\kiss.exe
%System%\kits.exe
%System%\litse.exe
%System%\manager.exe
%System%\mirc.exe
%System%\mss.exe
%System%\psycho.exe
%System%\pusyy.exe
%System%\r1.exe
%System%\stafsmirc.exe
%System%\userm.exe
%System%\werasd.exe
%System%\windows95.exe
%System%\wings.exe
%System%\winsys36.com
%System%\wintmp.exe
%Temp%\a.exe
%Temp%\pinoy pride v.2\mirc.exe
%Temp%\rarsfx0\kiss.exe
%Temp%\spoolsv.exe
%Windir%\config32\svchost.exe
%Windir%\driver cache\i386\spoolsv.exe
%Windir%\help\winhlp.exe
%Windir%\inf\svchost.exe
%Windir%\mirc.exe
%Windir%\msagent\inf\svchost.exe
%Windir%\pantek\svchost.exe
%Windir%\pif\lsass.exe
%Windir%\psycho.exe
%Windir%\servicepackfiles\i386\svhost.com
%Windir%\srchasst\csrsz.exe
%Windir%\system\kits.exe
%Windir%\system\svchost.exe
%Windir%\system\system\svchost.exe
%Windir%\temp\spool\spoolsv.exe
%Windir%\temp\spoolsv\spoolsv.exe
%Windir%\temp\tmp0000729b\daemon.exe
%Windir%\wauclt.exe
c:\mtscs.exe
c:\winnt\system32\lavan\system32.exe
c:\winnt\system32\os\system32.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.