Threat Search: 

ThreatExpert's Statistics for Trojan-Downloader.Agent!sd5 [PC Tools]:

Trojan-Downloader.Agent!sd5 [PC Tools] is also known as:
Threat AliasNumber of Incidents
TROJ_AGENT.VJC [Trend Micro]39,150
Trojan-Downloader.Win32.Agent.bfj [Kaspersky Lab]36,542
Backdoor.Trojan [Symantec]19,875
Generic.dx [McAfee]18,913
PE_CORELINK.C-O [Trend Micro]6,115
W32/Almanahe.dll [McAfee]6,115
Trojan-Downloader.Win32.Agent.bsi [Kaspersky Lab]5,512
W32.Almanahe.B [Symantec]2,881
Troj/Agent-FUR [Sophos]2,707
Trojan:Win32/Almanahe.E.dll [Microsoft]2,513
Trojan-Dropper.Agent [Ikarus]2,420
Win-Trojan/Alman.46592 [AhnLab]1,275
Bloodhound.Unknown [Symantec]1,034
Trojan-Downloader.Win32.Agent.dbt [Kaspersky Lab]1,014
Hacktool.Rootkit [Symantec]991
VirTool:WinNT/Knockex.D [Microsoft]731
Troj/Rootkit-DS [Sophos]624
Win-Trojan/Agent.3552 [AhnLab]338
Trojan-Downloader.Win32.Agent.lab [Kaspersky Lab]208
TrojanDownloader:Win32/Agent [Microsoft]199
W32.Mandaph [Symantec]182
Downloader [Symantec]156
Trojan-Downloader.Win32.Agent.gwh [Kaspersky Lab]142
New Malware.bx [McAfee]137
TROJ_AGENT.HVX [Trend Micro]130
Downloader.gen.a [McAfee]114
Virus.Win32.Alman.b [Kaspersky Lab]108
Trojan-Dropper.Agent [PC Tools]104
WORM_SOCKS.BL [Trend Micro]91
Trojan-Downloader.Small [Ikarus]78
Mal/Heuri-D, Mal/Koceg-A [Sophos]65
Trojan Horse [Symantec]53
Trojan-Downloader.Win32.Agent.akh [Kaspersky Lab]32
Trojan-Downloader.Win32.Agent.gdi [Kaspersky Lab]30
Generic.ff [McAfee]28
Backdoor.Knocker [PC Tools]26
Infostealer.Gampass [Symantec]26
Mal/Koceg-A [Sophos]26
Trojan-Downloader.Agent!ct [PC Tools]26
Win-Trojan/Agent.71680.BR [AhnLab]26
Matcash [McAfee]25
TROJ_DLOADER.LL [Trend Micro]25
Mal_Infostl [Trend Micro]24
Trojan.Adclicker [Symantec]23
TROJ_Generic [Trend Micro]22
Trojan-Downloader.Win32.Agent.bca [Kaspersky Lab]20
Generic Downloader [McAfee]19
TROJ_AGENT.AIAX [Trend Micro]18
Trojan-Downloader.Win32.Agent.atb [Kaspersky Lab]18
Trojan-Downloader.Win32.Agent.bnm [Kaspersky Lab]18
Adware-SoJus [McAfee]16
SecurityRisk.Downldr [Symantec]16
TROJ_AGENT.FCM [Trend Micro]16
TROJ_DLOADER.DFX [Trend Micro]16
Trojan-Downloader.Win32.Agent.apu [Kaspersky Lab]16
Trojan-Downloader.Win32.Agent.gah [Kaspersky Lab]15
Spy-Agent.bv [McAfee]14
Trojan-Downloader.Small.AAKR [Ikarus]13
Downloader.Trojan [Symantec]12
TROJ_AGENT.CZC [Trend Micro]12
Trojan-Downloader.Win32.Agent.avr [Kaspersky Lab]12
Trojan.Dropper [Symantec]11
Generic Downloader.ab [McAfee]10
Generic Downloader.z [McAfee]10
Generic Downloader.r [McAfee]9
TROJ_AGENT.FFY [Trend Micro]9
TROJ_DLOADER.JGY [Trend Micro]9
Trojan-Downloader.Win32.Agent.ebw [Kaspersky Lab]9
Trojan-Downloader.Win32.Agent.hnp [Kaspersky Lab]9
Mal/Generic-A [Sophos]8
TROJ_AGENT.ADPQ [Trend Micro]8
TROJ_AGENT.QKA [Trend Micro]8
Trojan-Downloader.Win32.Adload.jm [Kaspersky Lab]8
Trojan-Downloader.Win32.Agent.bls [Kaspersky Lab]8
W32.Monikey@mm [Symantec]8
Adware-MaxSearch [McAfee]7
Hacktool.Proxy [Symantec]7
Trojan-Downloader.Win32.Agent.bl [Kaspersky Lab]7
Trojan-Downloader.Win32.Agent.uj [Kaspersky Lab]7
Dialer.WebCont [Symantec]6
Downloader-BGX [McAfee]6
Infostealer [Symantec]6
TROJ_AGENT.TM [Trend Micro]6
TROJ_CLICKER.WI [Trend Micro]6
TROJ_DLOADER.DMI [Trend Micro]6
TROJ_VUNDO.AAO [Trend Micro]6
Trojan-Downloader.Win32.Agent.akq [Kaspersky Lab]6
Trojan-Downloader.Win32.Agent.auv [Kaspersky Lab]6
Trojan-Downloader.Win32.Agent.bes [Kaspersky Lab]6
Trojan-Downloader.Win32.Agent.bkd [Kaspersky Lab]6
Adware.MaxSearch [Symantec]5
Spam-Mailbot.f.gen [McAfee]5
TROJ_AGENT.RGN [Trend Micro]5
TROJ_AGENT.VIR [Trend Micro]5
TROJ_DLOADER.HGW [Trend Micro]5
TROJ_DLOADER.SM [Trend Micro]5
Trojan-Downloader.Win32.Agent.dve [Kaspersky Lab]5
Trojan-Downloader.Win32.Agent.tk [Kaspersky Lab]5
WORM_NUCRP.GEN [Trend Micro]5
Generic AdClicker.v [McAfee]4

Trojan-Downloader.Agent!sd5 [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
Netherlands32
Slovenia32
China18
France13
Russian Federation11
Canada6
United Kingdom5
Ukraine2
Brazil1
Italy1
Sweden1

Trojan-Downloader.Agent!sd5 [PC Tools] is known to be created as:
%AppData%\xlibgfl254.dll
%CommonPrograms%\startup\igfxtray.exe
%CommonPrograms%\startup\kunbang.exe
%ProgramFiles%\common files\system\msiwa32.exe
%ProgramFiles%\common files\system\smss.exe
%ProgramFiles%\common files\system\updaterun.exe
%ProgramFiles%\internet explorer\setupapi.dll
%ProgramFiles%\nodns\nodns.exe
%ProgramFiles%\outerinfo\oinfp.exe
%ProgramFiles%\router\router.exe
%ProgramFiles%\twain\twain.exe
%Programs%\startup\autostart.exe
%System%\cfcdfebedcbcb.dll
%System%\cftnom.exe
%System%\crypts.dll
%System%\csdqz.exe
%System%\csowe.exe
%System%\cssux.exe
%System%\csugv.exe
%System%\cszpf.exe
%System%\dicotta.exe
%System%\dlmain.dll
%System%\down.dll
%System%\drivers\9a6a.sys
%System%\drivers\inf\soconfig.exe
%System%\drivers\mcqc\adc.dll
%System%\drivers\sysdirmr.sys
%System%\dxdllreg.exe
%System%\ffservice.exe
%System%\fngdi.dll
%System%\hddguard.dll
%System%\iexplorer.exe
%System%\intenat.exe
%System%\jbsal.exe
%System%\judgemq.dll
%System%\kavv.dll
%System%\ldr.exe
%System%\lservice.exe
%System%\meex.com
%System%\meqjjts.exe
%System%\moviemk.exe
%System%\msfont.dll
%System%\mstscex.dll
%System%\mstsdsc.exe
%System%\nso12k.sys
%System%\oleauth32.dll
%System%\ppiep.dll
%System%\qmamxoe.exe
%System%\ravv.dll
%System%\regscan.exe
%System%\services.dll
%System%\socksys.dll
%System%\spool23.exe
%System%\srshost.exe
%System%\srshostu.exe
%System%\svchosts.exe
%System%\system.exe
%System%\systeminfocc.dll
%System%\sysudisk.exe
%System%\tahxqcj.dll
%System%\tmp_2.exe
%System%\tmp_36.exe
%System%\tmwsock.dll
%System%\wm.exe
%System%\wminotify.dll
%System%\wservice.exe
%System%\wuauc1t.exe
%System%\wups32.dll
%System%\xlibgfl254.dll
%System%\xyxuic.dll
%System%\yenapq15.dll
%Temp%\10110.exe
%Temp%\4.exe
%Temp%\clean_1fb07c.dll
%Temp%\g2-tmp.exe
%Temp%\g3-tmp.exe
%Temp%\keawaia.exe
%Temp%\loads.exe
%Temp%\sh.exe
%Temp%\svchost.exe
%Temp%\twain\twain.exe
%Temp%\weather_40.exe
%Temp%\wnset.exe
%Temp%\wuauclt.exe
%Temp%\zae.exe
%UserProfile%\tbfrfc.exe
%UserProfile%\windows\linkinfo.dll
%Windir%\config\csrss.exe
%Windir%\download\svhost32.exe
%Windir%\linkinfo.dll
%Windir%\mywork.exe
%Windir%\ntservice.exe
%Windir%\services32.dll
%Windir%\smss.exe
%Windir%\svchost.exe
%Windir%\taskmgr.exe
%Windir%\userinit.exe
c:\bot.exe
c:\dwnsetup\cone.exe
c:\explorer.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.