Threat Search: 

ThreatExpert's Statistics for Trojan.Cinmeng [PC Tools]:

Trojan.Cinmeng [PC Tools] is also known as:
Threat AliasNumber of Incidents
Trojan.Cinmeng [Symantec]124
Mal/Generic-A [Sophos]59
not-a-virus:AdWare.Win32.BHO.kup [Kaspersky Lab]50
Trojan:Win32/Cinmus.N [Microsoft]43
Adware-Cinmus!o [McAfee]40
Trojan:Win32/Cinmus.K [Microsoft]39
Mal/Behav-010, Mal/Behav-027 [Sophos]16
not-a-virus:AdWare.Win32.Cinmus.bkxm [Kaspersky Lab]16
Trojan.Win32.Cinmus [Ikarus]16
not-a-virus:AdWare.Win32.Cinmus.bcsb [Kaspersky Lab]12
Adware-Cinmus!k [McAfee]10
Mal/Behav-010 [Sophos]10
Win-Trojan/Cinmus.79620 [AhnLab]10
Adware-Cinmus.gen.u [McAfee]9
not-a-virus:AdWare.Win32.Cinmus [Ikarus]9
TROJ_CINMENG.HG [Trend Micro]9
Adware-Cinmus!f [McAfee]8
not-a-virus:AdWare.Win32.Cinmus.bkup [Kaspersky Lab]8
Adware-Cinmus.gen.p [McAfee]6
not-a-virus:AdWare.Win32.Cinmus.aizh [Kaspersky Lab]6
Troj/Cinmus-L [Sophos]5
not-a-virus:AdWare.Win32.BHO.krj [Kaspersky Lab]4
Trojan.Win32.BHO.lhc [Kaspersky Lab]3
Trojan:Win32/Malat [Microsoft]3
not-a-virus:AdWare.Win32.BHO.kto [Kaspersky Lab]2
not-a-virus:AdWare.Win32.BHO.kuw [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bgvq [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bgwg [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bhkk [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bhnf [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bhva [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bjuo [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bkot [Kaspersky Lab]2
not-a-virus:AdWare.Win32.Cinmus.bmtb [Kaspersky Lab]2
Win-Trojan/Cinmus.71568 [AhnLab]2
Win-Trojan/Cinmus.79598 [AhnLab]2
Adware-Cinmus [McAfee]1
Adware-Cinmus!l [McAfee]1
Adware-Cinmus!m [McAfee]1
Adware-Cinmus.gen.g [McAfee]1
Adware-Cinmus.gen.j [McAfee]1
Dropper/Malware.197677 [AhnLab]1
Gen.AdWare [Ikarus]1
Mal/Cimuz-J [Sophos]1
not-a-virus:AdWare.Win32.BHO.jss [Kaspersky Lab]1
not-a-virus:AdWare.Win32.BHO.kny [Kaspersky Lab]1
not-a-virus:AdWare.Win32.BHO.kog [Kaspersky Lab]1
not-a-virus:AdWare.Win32.BHO.kyh [Kaspersky Lab]1
not-a-virus:AdWare.Win32.Cinmus.bhxp [Kaspersky Lab]1
not-a-virus:AdWare.Win32.Cinmus.bibw [Kaspersky Lab]1
not-a-virus:AdWare.Win32.Cinmus.bmtc [Kaspersky Lab]1
Troj/Cinmus-M [Sophos]1
Trojan:Win32/Cinmus.P [Microsoft]1
Trojan-Clicker.Win32.Agent.jwf [Kaspersky Lab]1
Win-Trojan/Bho.163840.F [AhnLab]1
Win-Trojan/Cinmus.77824.AW [AhnLab]1
Win-Trojan/Cinmus.77824.BG [AhnLab]1
Win-Trojan/Cinmus.77824.BW [AhnLab]1
Win-Trojan/Cinmus.77824.CJ [AhnLab]1
Win-Trojan/Cinmus.79581 [AhnLab]1
Win-Trojan/Xema.variant [AhnLab]1

Trojan.Cinmeng [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
China15
Bulgaria2

Trojan.Cinmeng [PC Tools] is known to be created as:
%CommonAppData%\microsoft\media player\obj\wmpobj.sys
%CommonAppData%\microsoft\media player\wmp\mtlrd.sys
%CommonAppData%\microsoft\outlook express\2205.exe
%CommonAppData%\microsoft\outlook express\2339.exe
%Profiles%\5.exe
%ProgramFiles%\common files\1339.exe
%ProgramFiles%\microsoft office\system\sysbar.exe
%System%\sslsocket.dll
%System%\winldr.dll
%Temp%\36049734.exe
%Temp%\dosss11.dll
%Temp%\yoyo1182.exe
%Windir%\temp\42125.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.