Threat Search: 

ThreatExpert's Statistics for Mal/HckPk-A [Sophos]:

Mal/HckPk-A [Sophos] is also known as:
Threat AliasNumber of Incidents
Downloader-ASH.gen.b [McAfee]304
Joke.Blusod [Symantec]304
Application.BluSOD [PC Tools]261
New Malware.bl [McAfee]261
Trojan:Win32/Tibs.HP [Microsoft]219
Trojan Horse [Symantec]191
Trojan:Win32/Tibs.J [Microsoft]143
Infostealer.Gampass [Symantec]109
Suspicious.MH690 [Symantec]105
Trojan.Win32.Bohmini.A [Ikarus]77
Generic.dx [McAfee]74
PWS:Win32/Ldpinch.BC [Microsoft]64
Trojan-Downloader.Firu [Ikarus]58
Backdoor.Win32.Rukap.f [Ikarus]54
Trojan-Spy.Win32.Webmoner [Ikarus]53
New Malware.bj [McAfee]51
Joke-Bluescreen.c [McAfee]45
Win-Trojan/Midgare.34685 [AhnLab]40
Trojan.Peed [Ikarus]39
New Malware.fa [McAfee]38
Trojan.Win32.Midgare.mqa [Kaspersky Lab]37
Generic Downloader.x [McAfee]36
Generic.Trojan-Downloader.JKGD [Ikarus]33
Virus.Win32.Crypt.CIK [Ikarus]32
FakeAlert-AG [McAfee]27
SecurityRisk.Downldr [Symantec]27
Trojan.Crypt [Ikarus]25
Trojan-GameThief.Win32.OnLineGames.bmns [Kaspersky Lab]24
New Win32 [McAfee]23
Trojan.Generic [PC Tools]20
Win-Trojan/OnlineGameHack.20008.AE [AhnLab]18
Backdoor.Bifrose [Symantec]17
Trojan.Midgare.mqa [PC Tools]17
Trojan-GameThief.Win32.OnLineGames [Ikarus]17
Virus.Win32.Virut.ce [Kaspersky Lab]17
Win32/Virut.F [AhnLab]17
BackDoor-CEP!hv.a [McAfee]15
Trojan.Blusod [Symantec]15
Trojan.Skintrim [Symantec]15
Trojan-Dropper.Win32.Nemqe [Ikarus]15
Win32/NSAnti.suspicious [AhnLab]15
Packed.Generic.198 [Symantec]14
Packed.Generic.73 [Symantec]13
Win-Trojan/Xema.variant [AhnLab]13
Trojan-PSW.Gampass [PC Tools]12
Downloader [Symantec]11
Infostealer [Symantec]11
Spyware.Downldr!sd6 [PC Tools]11
W32.Virut.CF [Symantec]11
Downloader.gen.a [McAfee]10
PWS-LDPinch [McAfee]10
Trojan-Downloader.Win32.Small [Ikarus]10
Backdoor.Trojan [Symantec]9
New Poly Win32 [McAfee]9
P2P-Worm.Win32.SpyBot.gl [Ikarus]9
Trojan-Dropper.Agent [Ikarus]9
Generic Downloader.ab [McAfee]8
PWS:Win32/OnLineGames.N [Microsoft]8
Trojan:Win32/Tibs.GF [Microsoft]8
Trojan-GameThief.Win32.OnLineGames.vxme [Kaspersky Lab]8
Trojan.Peacomm [Symantec]7
Virus:Win32/Virut.BM [Microsoft]7
Generic Malware.co [McAfee]6
PWS-Mmorpg!cs [McAfee]6
PWS-Mmorpg.gen [McAfee]6
Trojan.Patchep [Symantec]6
Virus.Win32.Sality [Ikarus]6
W32.Ircbrute [Symantec]6
WORM_NUCRP.GEN [Trend Micro]6
Downloader-BAI!M711 [McAfee]5
Generic PWS.y [McAfee]5
New Malware.cn [McAfee]5
Packed.Generic.76 [Symantec]5
Trojan.Win32.Midgare [Ikarus]5
Trojan-Banker.Win32.Bancos [Ikarus]5
Virus.Win32.Agent.UWD [Ikarus]5
Virus.Win32.Bifrose [Ikarus]5
W32.Mixor.Q@mm [Symantec]5
W32.SillyFDC [Symantec]5
Backdoor.Win32.Haxdoor [Ikarus]4
Backdoor:Win32/Poison.M [Microsoft]4
Downloader-BAI.gen [McAfee]4
Generic BackDoor [McAfee]4
Mal_MLWR-1 [Trend Micro]4
Packed.Generic.114 [Symantec]4
PWS-Nemqe.dr [McAfee]4
Trojan.Agent.B!ct [PC Tools]4
Trojan.Packed.13 [Symantec]4
Trojan.Win32.Agent.ltz [Kaspersky Lab]4
Trojan.Win32.Midgare.nfv [Kaspersky Lab]4
Trojan:Win32/Tibs.gen!B [Microsoft]4
Trojan-Dropper.Win32.Delf [Ikarus]4
TrojanDropper:Win32/Nuwar.gen!lds [Microsoft]4
Virus.Win32.Delf.IFY [Ikarus]4
Win-Trojan/Agent.96256.AS [AhnLab]4
Backdoor.Win32.PoisonIvy.ay [Ikarus]3
Backdoor.Win32.VB [Ikarus]3
BackDoor-DSH [McAfee]3
Downloader.Trojan [Symantec]3
Email-Worm.Win32.VB.fn [Ikarus]3

Mal/HckPk-A [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
China154
Germany7
Russian Federation3
Spain3
Belgium1
Brazil1
Czech Republic1
Hong Kong1
Italy1
Japan1
Portugal1
Taiwan1
Turkey1
United Kingdom1

Mal/HckPk-A [Sophos] is known to be created as:
%AppData%\iecheck.exe
%LocalSettings%\soundmgr.exe
%ProgramFiles%\advancedvirusremover\pavrm.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bot\pad.exe
%ProgramFiles%\dj\qidong.exe
%ProgramFiles%\microsoft common\wuauclt.exe
%ProgramFiles%\r\rr.exe
%ProgramFiles%\sss.exe
%ProgramFiles%\wndooz\no.exe
%System%\adirss.exe
%System%\alsys.exe
%System%\aservr.exe
%System%\bifrost\server.exe
%System%\blphc35dj0erc1.scr
%System%\bluetoothauthorizationagent.exe
%System%\braviax.exe
%System%\cam\cam2.exe
%System%\csrcs.exe
%System%\csrsc.exe
%System%\ctfmona.exe
%System%\dbgrid32.exe
%System%\drivers\suchost.exe
%System%\drivers\txplatformm.exe
%System%\dsncb.exe
%System%\encapi.exe
%System%\face.exe
%System%\foxwei.exe
%System%\fwbmz.dll
%System%\h7co7rty.exe
%System%\ijp44tg.exe
%System%\isass.exe
%System%\j6erb4k.exe
%System%\jukla0s.exe
%System%\kb6kihf.exe
%System%\kivir.exe
%System%\ku03k28.exe
%System%\mcappr.exe
%System%\mcvsvm.exe
%System%\mcvsvr.exe
%System%\nd8pxp8.exe
%System%\prefetch\akma.exe
%System%\remotecomputer.exe
%System%\rmpwi02.exe
%System%\scvhost.exe
%System%\sdace.exe
%System%\spoolsvc.exe
%System%\sveran.exe
%System%\svhost.exe
%System%\syskgr.exe
%System%\system\svchost.exe
%System%\t0ugpc6.exe
%System%\tqfmgr.exe
%System%\trmp\tremp.exe
%System%\vmdetdhc.exe
%System%\vxshost.exe
%System%\w7fu04d.exe
%System%\wdfmgr32.exe
%System%\win_xs.exe
%System%\windres.exe
%System%\xfnx48h.exe
%System%\xitucdekssditpr.exe
%System%\zfeuipcpbleyrbr.exe
%Temp%\090612-a-4.exe
%Temp%\090614-1-7.exe
%Temp%\090615-3-2.exe
%Temp%\090615-4-3.exe
%Temp%\1017.exe
%Temp%\2.exe
%Temp%\baka.exe
%Temp%\dr.mot.exe
%Temp%\e253296t.exe
%Temp%\ie20.exe
%Temp%\mbcox32.exe
%Temp%\nbfile1.exe
%Temp%\pares.exe
%Temp%\player006.exe
%Temp%\rasman10.exe
%Temp%\sgcqexe.exe
%UserProfile%\lsass.exe
%UserProfile%\readme.exe
%UserProfile%\shmsnu1.exe
%Windir%\32\windows.exe
%Windir%\config\csrss.exe
%Windir%\dhcp\svchost.exe
%Windir%\mstwain32.exe
%Windir%\svchost.exe
%Windir%\system\smss.exe
%Windir%\twunk_64.exe
%Windir%\web\web2.exe
%Windir%\winnt.exe
c:\lsass.exe
c:\smss.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.