Threat Search: 

ThreatExpert's Statistics for Packed.Win32.NSAnti.r [Ikarus]:

Packed.Win32.NSAnti.r [Ikarus] is also known as:
Threat AliasNumber of Incidents
Packed.Win32.NSAnti.r [Kaspersky Lab]92
Infostealer.Gampass [Symantec]79
PWS-LegMir.dll [McAfee]78
Troj/Lineag-Gen [Sophos]63
TSPY_LEGMIR.CCJ [Trend Micro]14
Generic PWS.y [McAfee]12
Infostealer [Symantec]12
Trojan.Onlinegames.Gen!Pac.30 [PC Tools]12
TSPY_ONLINEG.IAT [Trend Micro]10
Trojan-Spy.Gampass!sd6 [PC Tools]7
Infostealer.Wowcraft [Symantec]6
PWS-LegMir [McAfee]6
PWS-WoW [McAfee]6
TSPY_WOWAR.AH [Trend Micro]5
Trojan-GameThief.Win32.WOW.sf [Kaspersky Lab]4
Trojan-PSW.Win32.OnLineGames.blt [Kaspersky Lab]4
Mal/Generic-A [Sophos]3
PWS-OnlineGames.a [McAfee]3
Trojan.PWS.OnLineGames.BCJ [PC Tools]3
Mal/Dropper-AE [Sophos]2
Mal/Generic-A, Troj/Virtum-Gen [Sophos]2
Mal/Packer [Sophos]2
PWS-Mmorpg.gen [McAfee]2
Troj/Lineag-CE [Sophos]2
Trojan-PSW.Win32.WOW.sf [Kaspersky Lab]2
TSPY_ONLINEG.NFL [Trend Micro]2
W32.Gammima.AG [Symantec]2
Adware.AproposMedia [PC Tools]1
Adware-Apropos.gen [McAfee]1
BrowserModifier:Win32/AproposMedia [Microsoft]1
Dropper/OnlineGameHack.429622 [AhnLab]1
Mal/EncPk-BW [Sophos]1
Mal/Packer, Mal/Behav-204, Mal/EncPk-F [Sophos]1
Mal/Packer, Mal/EncPk-BW [Sophos]1
Mal/Packer, Mal/EncPk-BW, Mal/Behav-329 [Sophos]1
Mal/RarMal-B [Sophos]1
Mal_MLWR-1 [Trend Micro]1
Packed/Upack [AhnLab]1
PE_PARITE.A [Trend Micro]1
Rootkit.Vanti [PC Tools]1
Rootkit.Win32.Vanti.dd [Kaspersky Lab]1
Spyware.Apropos [Symantec]1
Troj/LegMir-ARL [Sophos]1
Troj/Lineag-Gen, Mal/Behav-204 [Sophos]1
Trojan.KillAV [Symantec]1
Trojan.Packed.NsAnti [Symantec]1
Trojan:Win32/Inhoo.A [Microsoft]1
Trojan-Downloader.Win32.Agent.birg [Kaspersky Lab]1
Trojan-Downloader.Win32.Apropo.ag [Kaspersky Lab]1
Trojan-Dropper.Win32.Agent.airm [Kaspersky Lab]1
Trojan-GameThief.Win32.Magania.dsg [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.bdb [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.blt [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.goh [Kaspersky Lab]1
TSPY_NILAGE.AVI [Trend Micro]1
TSPY_ONLINEG.SEY [Trend Micro]1
VAnti [McAfee]1
Virus.Win32.Parite.b [Kaspersky Lab]1
Virus:Win32/Detnat.F [Microsoft]1
Virus:Win32/Parite.B [Microsoft]1
W32.Fujacks.B [Symantec]1
W32.Pinfi [Symantec]1
W32/Fujacks.worm [McAfee]1
W32/Parite-B [Sophos]1
W32/Pate.b [McAfee]1
Win32.Parite.B [PC Tools]1
Win32/Dellboy.M [AhnLab]1
Win32/Parite [AhnLab]1
Win-Trojan/Apropo.712704 [AhnLab]1
Win-Trojan/Vanti.16896.I [AhnLab]1
Worm.Delf!sd5 [PC Tools]1
Worm.Win32.Delf.bh [Kaspersky Lab]1
Worm:Win32/Emerleox.gen!A [Microsoft]1
WORM_ONLINEG.LTF [Trend Micro]1

Packed.Win32.NSAnti.r [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China4
Russian Federation1
Taiwan1

Packed.Win32.NSAnti.r [Ikarus] is known to be created as:
%System%\avpo0.dll
%System%\avpo1.dll
%System%\drivers\spoclsv.exe
%System%\kavo0.dll
%System%\kavo1.dll
%System%\kavo2.dll
%System%\scvhost.exe
%Temp%\kafan virlist 2009.03.05\090305-3-7.exe
%Windir%\g_server1.23.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.