Threat Search: 

ThreatExpert's Statistics for Mal/Pushdo-A [Sophos]:

Mal/Pushdo-A [Sophos] is also known as:
Threat AliasNumber of Incidents
TrojanDropper:Win32/Cutwail.AL [Microsoft]86
Trojan.Pandex [Symantec]47
FakeAlert-AG.gen.c [McAfee]32
FakeAlert-AG.gen.b [McAfee]30
Trojan Horse [Symantec]28
Trojan-Dropper.Kobcka [Ikarus]25
Trojan-Dropper.Win32.Cutwail [Ikarus]22
Downloader [Symantec]17
Trojan-Downloader.Win32.Cutwail [Ikarus]15
Generic Dropper [McAfee]13
Trojan.Win32.Agentb [Ikarus]13
Trojan:Win32/Meredrop [Microsoft]10
TrojanDownloader:Win32/Cutwail.AI [Microsoft]10
Trojan.Win32.Rabbit.ac [Kaspersky Lab]8
Cutwail [McAfee]6
Generic Downloader.x [McAfee]6
Trojan.Win32.Crypt.mv [Kaspersky Lab]6
Trojan.Win32.Rabbit [Ikarus]6
TrojanDownloader:Win32/Cutwail.Z [Microsoft]6
Spy-Agent.bv.gen.b [McAfee]5
Trojan.Kobcka [Ikarus]5
Trojan.Pandex!sd6 [PC Tools]5
Trojan:Win32/Cutwail.AQ [Microsoft]5
Trojan-Downloader.Win32.Cutwail.Z [Ikarus]5
Trojan-Dropper.Agent [Ikarus]5
Generic.dx [McAfee]4
Trojan.Dropper [Symantec]4
Trojan.Win32.Agent [Ikarus]4
Trojan.Win32.Rabbit.am [Kaspersky Lab]4
Win-Trojan/Rabbit.20478 [AhnLab]4
Backdoor.Trojan [Symantec]3
TROJ_SMALL.DOK [Trend Micro]3
Trojan.Win32.Crypt [Ikarus]3
Trojan.Win32.Crypt.mv [Ikarus]3
Trojan-Downloader.Win32.Agent.aslm [Kaspersky Lab]3
TrojanDownloader:Win32/Cutwail [Microsoft]3
TrojanDownloader:Win32/Cutwail.AE [Microsoft]3
TrojanDownloader:Win32/Cutwail.gen!C [Microsoft]3
Trojan-Dropper.Win32.Cutwail.AL [Ikarus]3
VirTool:WinNT/Cutwail.K [Microsoft]3
Generic Dropper.ez [McAfee]2
Generic PUP.x [McAfee]2
Trojan.Win32.Agent.alvf [Kaspersky Lab]2
Trojan.Win32.Agent.ampl [Kaspersky Lab]2
Trojan.Win32.Agent2 [Ikarus]2
Trojan.Win32.Crypt.acl [Kaspersky Lab]2
Trojan.Win32.Small.xpk [Kaspersky Lab]2
Trojan-Downloader.Win32.Cutwail.AD [Ikarus]2
TrojanDownloader:Win32/Cutwail.AD [Microsoft]2
TrojanDownloader:Win32/Cutwail.S [Microsoft]2
Trojan-Dropper.Win32.Agent.afvt [Kaspersky Lab]2
Virus.Trojan.Win32.Small.xpk [Ikarus]2
Win-Trojan/Agentb.22016.F [AhnLab]2
Win-Trojan/Downloader.21025 [AhnLab]2
Win-Trojan/Kobcka.21027 [AhnLab]2
Backdoor.Win32.Agent.tch [Kaspersky Lab]1
Backdoor.Win32.Small.hik [Kaspersky Lab]1
Backdoor.Win32.Small.hmt [Kaspersky Lab]1
Downloader.Trojan [Symantec]1
Dropper/Agent.32885 [AhnLab]1
Dropper/Agent.40448.BD [AhnLab]1
Dropper/Kobcka.40448 [AhnLab]1
Dropper/Rabbit.20477 [AhnLab]1
Dropper/Sibeair.22016 [AhnLab]1
FakeAlert-AB.dldr [McAfee]1
FakeAlert-AG [McAfee]1
Generic Downloader.x!bt [McAfee]1
Generic Downloader.x!i [McAfee]1
Generic Dropper!p [McAfee]1
Generic.dx!bj [McAfee]1
Generic.dx!cg [McAfee]1
Infostealer.Gampass [Symantec]1
PWS-Cashgrabber!a [McAfee]1
Spy-Agent.bv.dldr [McAfee]1
TROJ_PANDEX.DV [Trend Micro]1
TROJ_PUSHDO.DA [Trend Micro]1
TROJ_RSNET.RHB [Trend Micro]1
TROJ_SMALL.ESK [Trend Micro]1
TROJ_SMALL.MBZ [Trend Micro]1
Trojan.Agent!sd6 [PC Tools]1
Trojan.Agent2!sd6 [PC Tools]1
Trojan.Agentb!sd6 [PC Tools]1
Trojan.Inject [PC Tools]1
Trojan.Win32.Agent.acyy [Kaspersky Lab]1
Trojan.Win32.Agent.aecq [Kaspersky Lab]1
Trojan.Win32.Agent.aeuz [Kaspersky Lab]1
Trojan.Win32.Agent.afdt [Kaspersky Lab]1
Trojan.Win32.Agent.afgi [Kaspersky Lab]1
Trojan.Win32.Agent.afkv [Kaspersky Lab]1
Trojan.Win32.Agent.agzl [Kaspersky Lab]1
Trojan.Win32.Agent.ahqb [Kaspersky Lab]1
Trojan.Win32.Agent.ahqc [Kaspersky Lab]1
Trojan.Win32.Agent.aiba [Kaspersky Lab]1
Trojan.Win32.Agent.amov [Kaspersky Lab]1
Trojan.Win32.Agent.aoyu [Kaspersky Lab]1
Trojan.Win32.Agent.apck [Kaspersky Lab]1
Trojan.Win32.Agent.arnc [Kaspersky Lab]1
Trojan.Win32.Agent.asgf [Kaspersky Lab]1
Trojan.Win32.Agent.asiv [Kaspersky Lab]1
Trojan.Win32.Agent.asqn [Kaspersky Lab]1

Mal/Pushdo-A [Sophos] is known to be created as:
%System%\cpl32ver.exe
%System%\msmsgrs.exe
%System%\reader.exe
%System%\reader_s.exe
%System%\rs32net.exe
%UserProfile%\reader_s.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).