Threat Search: 

ThreatExpert's Statistics for Puper [McAfee]:

Puper [McAfee] is also known as:
Threat AlaisNumber of Incidents
Trojan.Zlob [Symantec]920
Adware.Agent.BN [PC Tools]727
Trojan.Popuper [PC Tools]195
Trojan.DL.Zlob.Gen.34 [PC Tools]149
not-a-virus:AdWare.Win32.Vapsup.wl [Kaspersky Lab]102
Trojan-Downloader.Zlob!sd5 [PC Tools]63
Trojan-Downloader.Win32.Zlob.fjb [Kaspersky Lab]43
Trojan.Zlob.Gen.41 [PC Tools]40
not-a-virus:AdWare.Win32.Vapsup.vz [Kaspersky Lab]31
Trojan.Emcodec [Symantec]30
Trojan-Downloader.Win32.Zlob.cee [Kaspersky Lab]30
Trojan Horse [Symantec]26
TROJ_ZLOB.CPP [Trend Micro]25
TROJ_ZLOB.MT [Trend Micro]21
Downloader [Symantec]20
Possible_Virus [Trend Micro]20
Trojan-Downloader.Win32.Zlob.bpn [Kaspersky Lab]20
TROJ_ZLOB.ECJ [Trend Micro]17
TROJ_AGENT.YTI [Trend Micro]16
TROJ_ZLOB.BFO [Trend Micro]16
TROJ_ZLOB.BUN [Trend Micro]16
Trojan.StartPage [Symantec]16
Trojan-Downloader.Win32.Zlob.bqw [Kaspersky Lab]16
Trojan-Downloader.Win32.Zlob.cpx [Kaspersky Lab]16
TROJ_ZLOB.EQO [Trend Micro]15
Trojan-Downloader.Win32.Zlob.jl [Kaspersky Lab]15
Bloodhound.Unknown [Symantec]13
Trojan-Downloader.Win32.Zlob.eka [Kaspersky Lab]13
Trojan-Downloader.Win32.Zlob.fjc [Kaspersky Lab]13
Trojan-Downloader.Win32.Zlob.boo [Kaspersky Lab]12
Trojan-Downloader.Win32.Zlob.btq [Kaspersky Lab]11
Trojan.FakeAlert [PC Tools]10
Trojan-Clicker.Agent!sd5 [PC Tools]10
Trojan-Clicker.Win32.Agent.gy [Kaspersky Lab]10
TROJ_ZLOB.ALI [Trend Micro]9
Trojan-Downloader.Win32.Zlob.egm [Kaspersky Lab]9
TROJ_VB.FFB [Trend Micro]8
TROJ_ZLOB.BVP [Trend Micro]8
Trojan.Zlob.H [Symantec]8
Packed/Upack [PC Tools]7
TROJ_ZLOB.CVQ [Trend Micro]7
Trojan.DL.Zlob.Gen.43 [PC Tools]7
TROJ_ZLOB.AKK [Trend Micro]6
TROJ_ZLOB.AXI [Trend Micro]6
Trojan-Downloader.Win32.Zlob.bov [Kaspersky Lab]6
TROJ_ZLOB.AGQ [Trend Micro]5
Trojan.Zlob.M [Symantec]5
Trojan-Downloader.Win32.Zlob.btj [Kaspersky Lab]5
TROJ_BHO.IN [Trend Micro]4
TROJ_BHO.KF [Trend Micro]4
TROJ_ZLOB.AEH [Trend Micro]4
TROJ_ZLOB.AEX [Trend Micro]4
TROJ_ZLOB.AEY [Trend Micro]4
TROJ_ZLOB.BCB [Trend Micro]4
TROJ_ZLOB.BXG [Trend Micro]4
TROJ_ZLOB.CET [Trend Micro]4
TROJ_ZLOB.DSG [Trend Micro]4
TROJ_ZLOB.SP [Trend Micro]4
TROJ_ZLOB.VF [Trend Micro]4
Trojan.Adclicker [Symantec]4
Trojan.Zlob.Gen.11 [PC Tools]4
Trojan-Downloader.Win32.Zlob.boi [Kaspersky Lab]4
Trojan-Downloader.Win32.Zlob.cwl [Kaspersky Lab]4
Trojan-Downloader.Win32.Zlob.ijd [Kaspersky Lab]4
Trojan-Downloader.Win32.Zlob.jy [Kaspersky Lab]4
Trojan-Downloader.Win32.Zlob.jz [Kaspersky Lab]4
Trojan-Downloader.Zlob.GEN [PC Tools]4
Trojan-Dropper.Win32.Small.ava [Kaspersky Lab]4
W32.Spybot.Worm [Symantec]4
WORM_NUCRP.GEN [Trend Micro]4
Possible_Zlob [Trend Micro]3
Possible_Zlob-1 [Trend Micro]3
TROJ_ZLOB.BFP [Trend Micro]3
TROJ_ZLOB.BHO [Trend Micro]3
TROJ_ZLOB.DSW [Trend Micro]3
TROJ_ZLOB.EGG [Trend Micro]3
TROJ_ZLOB.EQE [Trend Micro]3
TROJ_ZLOB.ESG [Trend Micro]3
TROJ_ZLOB.GEN [Trend Micro]3
TROJ_ZLOB.TH [Trend Micro]3
Trojan.Dropper [Symantec]3
Trojan.Virtumonde [PC Tools]3
Trojan.Win32.Zapchast.bb [Kaspersky Lab]3
Trojan.Zapchast!sd5 [PC Tools]3
Trojan-Downloader.Popuper [PC Tools]3
Trojan-Downloader.Win32.Zlob.cba [Kaspersky Lab]3
Trojan-Downloader.Win32.Zlob.cdj [Kaspersky Lab]3
Trojan-Downloader.Win32.Zlob.eie [Kaspersky Lab]3
Packed.Win32.PolyCrypt.b [Kaspersky Lab]2
TROJ_BHO.AY [Trend Micro]2
TROJ_DLOADER.TDF [Trend Micro]2
TROJ_Generic [Trend Micro]2
TROJ_PUPER.BS [Trend Micro]2
TROJ_ZLOB.AHQ [Trend Micro]2
TROJ_ZLOB.AMS [Trend Micro]2
TROJ_ZLOB.AWV [Trend Micro]2
TROJ_ZLOB.COB [Trend Micro]2
TROJ_ZLOB.CTW [Trend Micro]2
TROJ_ZLOB.DCW [Trend Micro]2
TROJ_ZLOB.DDR [Trend Micro]2

Puper [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation61
Ukraine31
Spain7
Republic of Korea1

Puper [McAfee] is known to be created as:
%CommonAppData%\axizwnmh.dll
%CommonAppData%\ejyxchcj.dll
%CommonAppData%\grqvifar.dll
%CommonAppData%\wtgxodij.dll
%CommonAppData%\yfydypgx.dll
%ProgramFiles%\adultaccess\uninstall.exe
%ProgramFiles%\helper\1199747698.dll
%ProgramFiles%\helper\1199747699.dll
%ProgramFiles%\internet security\iesuninst.exe
%ProgramFiles%\media-codec\uninst.exe
%ProgramFiles%\netproject\sbmdl.dll
%ProgramFiles%\netproject\sbmntr.exe
%ProgramFiles%\netproject\sbsm.exe
%ProgramFiles%\netproject\wamdl.dll
%ProgramFiles%\netproject\waun.exe
%ProgramFiles%\sotfone\1199747698.dll
%ProgramFiles%\videoaccess\uninstall.exe
%ProgramFiles%\videoaccesscodec\uninstall.exe
%System%\bpmini.exe
%System%\conime\conime.dll
%System%\dcggain.dll
%System%\hggdaaw.dll
%System%\icmntr.exe
%System%\ieffse32.dll
%System%\iesmin.exe
%System%\iesplg.dll
%System%\isadd.dll
%System%\isamini.exe
%System%\isfmdl.dll
%System%\isfmm.exe
%System%\ixt0.dll
%System%\kdgpi.exe
%System%\kdqpj.exe
%System%\kdwdy.exe
%System%\pmmnt.exe
%System%\regmod.exe
%System%\sbmdl.dll
%System%\sbsm.exe
%System%\scm.exe
%System%\vtuvttrs.dll
%Temp%\ac8zt2\main_uninstaller.exe
%Temp%\ac8zt2\rmv.exe
%Temp%\cnsqtkrwxr.exe
%Temp%\dvd.idle.pro.v5.9.8.5.winall.cracked-brd\cracks\patch.exe
%Temp%\keygen.exe
%Temp%\laf4.exe
%Temp%\larm.dll
%Temp%\mozzi.exe
%Temp%\mxstat.exe
%Temp%\online video add-on\icun.exe
%Temp%\online video add-on\isfmdl.dll
%Temp%\online video add-on\isfmntr.exe
%Temp%\routipnfd.exe
%Temp%\sockappgkv.exe
%Temp%\uninst.exe
%Temp%\vpncore.exe
%Windir%\bgntlvo.dll
%Windir%\bklgvsf.dll
%Windir%\bmlvqkn.dll
%Windir%\dls0523pmw.exe
%Windir%\dopfwrlgfm.dll
%Windir%\ensfolr.dll
%Windir%\epxonwo.dll
%Windir%\gormet.dll
%Windir%\kopmet.dll
%Windir%\pandsf.dll
%Windir%\wireless\wireless.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.