Threat Search: 

ThreatExpert's Statistics for Trojan-Downloader.Win32.Dontovo [Ikarus]:

Trojan-Downloader.Win32.Dontovo [Ikarus] is also known as:
Threat AliasNumber of Incidents
FakeAlert-ES [McAfee]30
Trojan.Win32.FraudPack.pfw [Kaspersky Lab]29
Win-Trojan/Fraudpack.25088.F [AhnLab]24
Mal/Generic-A [Sophos]15
Trojan Horse [Symantec]11
Trojan.Win32.FraudPack.pjs [Kaspersky Lab]6
Win-Trojan/Downloader.27648.IF [AhnLab]6
Trojan.Win32.FraudPack.pto [Kaspersky Lab]4
Mal/FakeAV-WEB [Sophos]2
Downloader [Symantec]1
Trojan.Win32.FraudPack.ovb [Kaspersky Lab]1

Trojan-Downloader.Win32.Dontovo [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation2

Trojan-Downloader.Win32.Dontovo [Ikarus] is known to be created as:
%ProgramFiles%\adult tube xxx codec\antivirus\codec.exe
%ProgramFiles%\adult tube xxx codec\antivirus\install.exe
%Temp%\7zs1.tmp\keygen.exe
%Temp%\nsi2.tmp\db.exe
%Windir%\codec.exe
%Windir%\video.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.