Threat Search: 

ThreatExpert's Statistics for Trojan-Downloader.Small [Ikarus]:

Trojan-Downloader.Small [Ikarus] is also known as:
Threat AliasNumber of Incidents
Trojan-Downloader.Win32.Agent.bexw [Kaspersky Lab]700
Mal/Generic-A [Sophos]586
Downloader [Symantec]531
Generic Downloader.x [McAfee]528
Trojan-Downloader.Agent!sd6 [PC Tools]500
Win-Trojan/Yanshi.3072 [AhnLab]450
Trojan-Dropper.Agent [Ikarus]375
TrojanDownloader:Win32/Troxen!rts [Microsoft]275
Trojan-Downloader.Win32.Agent.lab [Kaspersky Lab]127
W32.Mandaph [Symantec]116
Trojan.Generic [Ikarus]100
Generic.dx [McAfee]91
Trojan-Downloader.Agent!sd5 [PC Tools]78
WORM_SOCKS.BL [Trend Micro]74
TROJ_AGENT.HVX [Trend Micro]60
Mal/Heuri-D, Mal/Koceg-A [Sophos]56
TrojanDownloader:Win32/Agent!rts [Microsoft]50
Mal/Inet-Fam [Sophos]35
Trojan.Win32.Agent.cepl [Kaspersky Lab]35
Backdoor.Koceg.E [PC Tools]26
Downloader.gen.a [McAfee]26
Mal/Koceg-A [Sophos]18
Win-Trojan/Agent.71680.BR [AhnLab]17
Win-Trojan/Downloader.19968.LF [AhnLab]14
Trojan-Downloader.Agent!ct [PC Tools]12
Trojan-Downloader.Small.AAKR [Ikarus]11
Trojan Horse [Symantec]9
Trojan.Generic [PC Tools]7
Mal/EncPk-FC [Sophos]6
Trojan-Downloader.Small.AET [Ikarus]4
Mal/EncPk-CZ [Sophos]2
Packed.Win32.Katusha.a [Kaspersky Lab]2
Backdoor.Hupigon.HMW [PC Tools]1
Backdoor.Win32.Hupigon.ugc [Kaspersky Lab]1
Backdoor:Win32/Hupigon.WZ [Microsoft]1
Backdoor:Win32/Koceg.gen!A [Microsoft]1
BackDoor-DRW [McAfee]1
Downloader.MisleadApp [Symantec]1
Downloader-BDJ [McAfee]1
Generic Downloader.q [McAfee]1
Generic PUP.x [McAfee]1
Generic.dx!fqj [McAfee]1
Mal/Basine-C [Sophos]1
Troj/Banker-ERT [Sophos]1
Troj/Dloadr-BXU [Sophos]1
Troj/Hupigon-TB [Sophos]1
TROJ_MNLESS.BR [Trend Micro]1
Trojan.DR.Renos.Gen.6 [PC Tools]1
Trojan-Downloader.Small!sd6 [PC Tools]1
Trojan-Downloader.Win32.Small.afkf [Kaspersky Lab]1
Trojan-Downloader.Win32.Small.hei [Kaspersky Lab]1
Trojan-Downloader.Win32.Tiny.cdk [Kaspersky Lab]1
TrojanDownloader:Win32/Tiny.GV [Microsoft]1
TrojanDownloader:Win32/Zlob [Microsoft]1
Win-Trojan/Fraudpack.49156 [AhnLab]1
Win-Trojan/Xema.variant [AhnLab]1
Worm.Koceg.Gen [PC Tools]1
Worm.Win32.Socks.hy [Kaspersky Lab]1

Trojan-Downloader.Small [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
United Kingdom1

Trojan-Downloader.Small [Ikarus] is known to be created as:
%AppData%\cftmon.exe
%System%\6to4v32.dll
%System%\drivers\dcbcg.exe
%System%\drivers\spools.exe
%System%\lspfxc.dll
%System%\lspglh.dll
%System%\lspike.dll
%System%\telem32.dll
%Temp%\1aa73.dll
%Temp%\1ab7d.dll
%Temp%\2de40.dll
%Temp%\32a9b.dll
%Temp%\333d3.dll
%Temp%\33aa9.dll
%Temp%\39ce76.dll
%Temp%\39cf02.dll
%Temp%\39d079.dll
%Temp%\39d164.dll
%Temp%\3a1cf4.dll
%Temp%\3a1d42.dll
%Temp%\3a1d51.dll
%Temp%\3a1ec8.dll
%Temp%\3a1f74.dll
%Temp%\3a1fc2.dll
%Temp%\3a1fe2.dll
%Temp%\3a2030.dll
%Temp%\3a2253.dll
%Temp%\3a2550.dll
%Temp%\3a25cd.dll
%Temp%\3a2689.dll
%Temp%\3a2763.dll
%Temp%\3a2773.dll
%Temp%\3a27e0.dll
%Temp%\3a2948.dll
%Temp%\3a2b1d.dll
%Temp%\3a352f.dll
%Temp%\3a559.dll
%Temp%\3a5f5.dll
%Temp%\3ab64.dll
%Temp%\3ade5.dll
%Temp%\3ae42.dll
%Temp%\3f30c.dll
%Temp%\3faeb.dll
%Temp%\3fb49.dll
%Temp%\3fb68.dll
%Temp%\3fc33.dll
%Temp%\3fc53.dll
%Temp%\3fca1.dll
%Temp%\3fcef.dll
%Temp%\3fd5c.dll
%Temp%\3fd6c.dll
%Temp%\3fef3.dll
%Temp%\40115.dll
%Temp%\40173.dll
%Temp%\4026d.dll
%Temp%\4077e.dll
%Temp%\40859.dll
%Temp%\47089.dll
%Temp%\470f6.dll
%Temp%\4727d.dll
%Temp%\47617.dll
%Temp%\4778e.dll
%Temp%\47914.dll
%Temp%\4be89.dll
%Temp%\4c55f.dll
%Temp%\4c56f.dll
%Temp%\4cade.dll
%Temp%\4cc16.dll
%Temp%\4ce49.dll
%Temp%\4d388.dll
%Temp%\4d454.dll
%Temp%\4d8c8.dll
%Temp%\56856.dll
%Temp%\loads.exe
%Temp%\mbam.exe
%Temp%\sh.exe
%Temp%\zae.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).