Threat Search: 

ThreatExpert's Statistics for Packed.Win32.Krap.w [Kaspersky Lab]:

Packed.Win32.Krap.w [Kaspersky Lab] is also known as:
Threat AliasNumber of Incidents
Packed.Generic.243 [Symantec]101
Packed.Win32.Krap [Ikarus]72
Trojan.Win32.Bredolab [Ikarus]54
Mal/Generic-A [Sophos]48
PWS:Win32/Zbot.gen!R [Microsoft]36
Trojan:Win32/Winwebsec [Microsoft]26
PWS:Win32/Yahoopass.H [Microsoft]19
Mal/BredoPk-B [Sophos]16
Mal/FakeAV-AD [Sophos]16
Win-Trojan/Krap.104448.C [AhnLab]15
FakeAlert-DZ [McAfee]14
HeurEngine.MaliciousPacker [PC Tools]13
Mal/Krap-B, Mal/BredoPk-B [Sophos]13
Trojan Horse [Symantec]13
FakeAlert-WinwebSecurity.gen [McAfee]12
Generic PWS.ch [McAfee]12
Mal/Bredo-A, Mal/Behav-340 [Sophos]11
Mal/Bredo-A, Mal/BredoPk-B [Sophos]11
Trojan.Generic [PC Tools]11
Backdoor:Win32/Qakbot.gen!A [Microsoft]9
Mal/EncPk-JX [Sophos]8
Mal/EncPk-MZ [Sophos]8
Mal/FakeAV-AD, Mal/EncPk-JX [Sophos]8
Backdoor.Win32.Bredavi [Ikarus]7
Mal/Bredo-A [Sophos]7
Malware.Qakbot [PC Tools]7
W32.Qakbot [Symantec]7
Backdoor.Win32.Qakbot [Ikarus]6
Bredolab.gen.a [McAfee]6
Mal/Bredo-E, Mal/Bredo-E, Mal/Bredo-F [Sophos]6
Trojan:Win32/Glecia.gen!A [Microsoft]6
TrojanDownloader:Win32/Waledac.C [Microsoft]6
Win-Trojan/Krap.52736.D [AhnLab]6
Trojan-Downloader.Win32.Bredolab [Ikarus]5
Bredolab.gen.h [McAfee]4
Packed.Generic.272 [Symantec]4
Packed.Generic.276 [Symantec]4
PWS.Win32 [Ikarus]4
TrojanDownloader:Win32/Harnig.gen!J [Microsoft]4
Win-Trojan/Bredolab.Gen [AhnLab]4
Generic Obfuscated.d [McAfee]3
Mal/Behav-340 [Sophos]3
Mal/Bredo-A, Mal/Behav-340, Mal/BredoPk-B [Sophos]3
Mal/Krap-B [Sophos]3
Trojan.Bredolab [Symantec]3
TrojanSpy:Win32/Bebloh.A [Microsoft]3
Win-Trojan/Malware.40960.H [AhnLab]3
FakeAlert-GM [McAfee]2
Generic PWS.y!byc [McAfee]2
Generic.dx!mbh [McAfee]2
Infostealer.Banker.C [Symantec]2
Mal/Bredo-E, Mal/Bredo-E [Sophos]2
Mal/FakeAV-AD, Mal/BredoPk-B [Sophos]2
Mal/Generic-A, Mal/Bredo-E, Mal/Bredo-E [Sophos]2
Mal/Generic-L [Sophos]2
Mal/Qbot-B [Sophos]2
Packed.Generic.230 [Symantec]2
Packed.Generic.269 [Symantec]2
Possible_Virus [Trend Micro]2
PWS:Win32/Zbot.PG [Microsoft]2
Trojan.Zbot [PC Tools]2
Trojan.Zbot [Symantec]2
Trojan-Downloader.Win32.Agent.bqxc [Kaspersky Lab]2
TrojanDownloader:Win32/Bredolab.AB [Microsoft]2
TrojanDownloader:Win32/Harnig.gen!L [Microsoft]2
Trojan-PSW.Banker [PC Tools]2
W32/Akbot!a [McAfee]2
Backdoor.Bredolab.sie [PC Tools]1
Backdoor.Trojan [PC Tools]1
Backdoor.Trojan [Symantec]1
Backdoor.Win32.Votwup [Ikarus]1
Backdoor:Win32/Votwup.A [Microsoft]1
Bredolab.gen.c [McAfee]1
Downloader [Symantec]1
Downloader.Generic [PC Tools]1
Downloader-CAQ [McAfee]1
Dropper/Malware.188928 [AhnLab]1
Dropper/Malware.18944.G [AhnLab]1
Dropper/Rustock.134656 [AhnLab]1
Gen.Heur [Ikarus]1
Generic Downloader.x!bns [McAfee]1
Generic Proxy!r [McAfee]1
Generic PWS.y!bsk [McAfee]1
Generic PWS.y!bvn [McAfee]1
Generic PWS.y!bwq [McAfee]1
Generic PWS.y!ur [McAfee]1
Generic PWS.y!yg [McAfee]1
Generic.dx!fhi [McAfee]1
Generic.dx!fvx [McAfee]1
Generic.dx!mgw [McAfee]1
Generic.dx!mja [McAfee]1
Generic.dx!noo [McAfee]1
Mal/Bredo-A, Mal/Behav-340, Mal/Behav-204 [Sophos]1
Mal/Bredo-E, Mal/Bredo-E, Mal/Bredo-F, Mal/Qbot-B [Sophos]1
Mal/Bredo-E, Mal/Bredo-E, Mal/Qbot-B [Sophos]1
Mal/BredoPk-B, Mal/Bredo-E, Mal/Bredo-E, Mal/BredoPk-B [Sophos]1
Mal/BredoPk-B, Mal/Bredo-E, Mal/Bredo-E, Mal/BredoPk-B, Mal/Bredo-F [Sophos]1
Mal/EncPk-JB, Mal/Behav-204 [Sophos]1
Mal/EncPk-JX, Mal/BredoPk-B [Sophos]1
Mal/EncPk-MP, Mal/Qbot-B [Sophos]1

Packed.Win32.Krap.w [Kaspersky Lab] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation201
Taiwan3
China1

Packed.Win32.Krap.w [Kaspersky Lab] is known to be created as:
%AppData%\ktbrtbsacs.dll
%AppData%\vjxjeu\youlsysguard.exe
%CommonAppData%\11143754\11143754.exe
%CommonAppData%\11565624\11565624.exe
%CommonAppData%\11611254\11611254.exe
%CommonAppData%\11628124\11628124.exe
%CommonAppData%\11702034\11702034.exe
%CommonAppData%\11756874\11756874.exe
%CommonAppData%\11762504\11762504.exe
%CommonAppData%\11772654\11772654.exe
%CommonAppData%\11906874\11906874.exe
%CommonAppData%\11909214\11909214.exe
%CommonAppData%\11913434\11913434.exe
%CommonAppData%\11946404\11946404.exe
%CommonAppData%\11947654\11947654.exe
%CommonAppData%\11963434\11963434.exe
%CommonAppData%\12111254\12111254.exe
%CommonAppData%\12118754\12118754.exe
%CommonAppData%\12149684\12149684.exe
%CommonAppData%\12150314\12150314.exe
%CommonAppData%\12154684\12154684.exe
%CommonAppData%\12155314\12155314.exe
%CommonAppData%\12155784\12155784.exe
%CommonAppData%\12157814\12157814.exe
%CommonAppData%\12174684\12174684.exe
%CommonAppData%\12182344\12182344.exe
%CommonAppData%\12309684\12309684.exe
%CommonAppData%\12359844\12359844.exe
%CommonAppData%\12363284\12363284.exe
%CommonAppData%\12366094\12366094.exe
%CommonAppData%\17447184\17447184.exe
%CommonAppData%\microsoft\vmonitor.exe
%ProgramFiles%\internet explorer\connection wizard\icwsetup.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\plugin.exe
%Programs%\startup\isqsys32.exe
%Programs%\startup\rarype32.exe
%System%\ivvgviwuor.exe
%System%\moyx.exe
%System%\qtplugin.exe
%System%\sdra64.exe
%System%\servises.exe
%System%\wbem\proquota.exe
%Temp%\eojgkrco.exe
%Temp%\iexplore.exe
%Temp%\is-qetds.tmp\kepriduko.dll
%Temp%\load.exe
%Windir%\temp\_ex-08.exe
%Windir%\temp\wpv091256600826.exe
%Windir%\temp\wpv101256600826.exe
%Windir%\temp\wpv111251459151.exe
%Windir%\temp\wpv181248050836.exe
%Windir%\temp\wpv471248050836.exe
%Windir%\temp\wpv481256600826.exe
%Windir%\temp\wpv511256600826.exe
%Windir%\temp\wpv551256600826.exe
%Windir%\temp\wpv591256600826.exe
%Windir%\temp\wpv601251296984.exe
%Windir%\temp\wpv711256600826.exe
%Windir%\temp\wpv721256600826.exe
%Windir%\temp\wpv781256600826.exe
%Windir%\temp\wpv791256600826.exe
%Windir%\temp\wpv821251296984.exe
%Windir%\temp\wpv891256600826.exe
%Windir%\temp\wpv901256600826.exe
%Windir%\temp\wpv921256600826.exe
%Windir%\temp\wpv951251296984.exe
%Windir%\temp\wpv961255601141.exe
%Windir%\updatd7.exe
%Windir%\winlogon.exe
c:\dntddho.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.