Threat Search: 

ThreatExpert's Statistics for Rootkit.Agent.EX [PC Tools]:

Rootkit.Agent.EX [PC Tools] is also known as:
Threat AliasNumber of Incidents
Generic Rootkit.d [McAfee]19,668
Rootkit.Win32.Agent.ex [Kaspersky Lab]19,149
Hacktool.Rootkit [Symantec]19,148
TrojanSpy:Win32/Ursnif [Microsoft]19,008
TROJ_ROOTKIT.FX [Trend Micro]18,216
Troj/Rootkit-DK [Sophos]18,085
Rootkit.Win32.Agent.ex [Ikarus]15,420
Win-Trojan/Agent.8192.BP [AhnLab]6,336
Rootkit.Agent.CZBC [PC Tools]792
Infostealer.Snifula [Symantec]702
TROJ_AGENT.CWT [Trend Micro]621
Rootkit.Win32.Agent.sz [Kaspersky Lab]432
Mal/Generic-A [Sophos]162
VirTool:WinNT/Ursnif.A [Microsoft]162
Win-Trojan/Agent.7680.CN [AhnLab]108
Generic RootKit.a [McAfee]43
Rootkit.Agent!ct [PC Tools]27
Rootkit.Win32.Agent.ef [Kaspersky Lab]20
RTKT_AGENT.ADRX [Trend Micro]20
Infostealer.Snifula.B [Symantec]19
TROJ_SMALL.EME [Trend Micro]17
Trojan-PSW.Win32.Small.bs [Kaspersky Lab]17
TROJ_AGENT.TEL [Trend Micro]9
Rootkit.Win32.Agent.enw [Kaspersky Lab]4
Trojan Horse [Symantec]4
Infostealer [Symantec]3
Infostealer.Snifula.C [Symantec]3
Spy-Agent.bg [McAfee]3
Troj/Agent-FVL [Sophos]3
Trojan.Win32.Agent [Ikarus]3
Trojan.Win32.Agent.atsa [Kaspersky Lab]3
FormSpy [McAfee]1
Generic Dropper.ad [McAfee]1
Generic Packed [McAfee]1
Generic PWS.o [McAfee]1
Mal/EncPk-HJ [Sophos]1
RTKT_SMALL.DQB [Trend Micro]1
Troj/Agent-HXS [Sophos]1
Troj/NtRootK-AO [Sophos]1
TROJ_AGENT.ANZC [Trend Micro]1
Trojan.Win32.Pakes [Ikarus]1
Trojan.Win32.Pakes.lbn [Kaspersky Lab]1
Trojan:Win32/Goldun [Microsoft]1
Trojan-Downloader.Win32.Injecter.cpz [Kaspersky Lab]1
Trojan-PSW.Win32.Papras.cf [Kaspersky Lab]1
Trojan-PSW.Win32.Papras.dh [Kaspersky Lab]1
Trojan-PSW.Win32.Papras.ga [Kaspersky Lab]1
Trojan-PSW.Win32.Papras.o [Kaspersky Lab]1
Trojan-PWS.Papras [Ikarus]1
Trojan-PWS.Win32.Papras.cf [Ikarus]1
Trojan-PWS.Win32.Small.bs [Ikarus]1
TrojanSpy:Win32/Agent.BI [Microsoft]1
TrojanSpy:Win32/Ursnif.B [Microsoft]1
TrojanSpy:Win32/Ursnif.Q [Microsoft]1
TSPY_PAPRAS.AD [Trend Micro]1
TSPY_PAPRAS.BR [Trend Micro]1
TSPY_PAPRAS.CF [Trend Micro]1
Win-Trojan/Papras.35328.D [AhnLab]1

Rootkit.Agent.EX [PC Tools] is known to be created as:
%Windir%\9129837.exe
%Windir%\hide_evr2.sys
%Windir%\new_drv.sys
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.