Threat Search: 

ThreatExpert's Statistics for Trojan-Downloader.Win32.Exchanger [Ikarus]:

Trojan-Downloader.Win32.Exchanger [Ikarus] is also known as:
Threat AliasNumber of Incidents
TrojanDownloader:Win32/Cbeplay.E [Microsoft]12
Generic Downloader.x [McAfee]10
Troj/Agent-IXR [Sophos]9
Trojan-Downloader.Win32.Exchanger.att [Kaspersky Lab]9
Mal/EncPk-DA [Sophos]7
Trojan-Downloader.Exchanger!sd6 [PC Tools]7
BackDoor-DNM [McAfee]6
Downloader [Symantec]5
Mal/EncPk-DA, Mal/TibsPak [Sophos]5
Tibs-Packed [McAfee]5
Trojan.Erotpics [Symantec]5
Trojan.Pandex [Symantec]4
TROJ_NUWAR.GFZ [Trend Micro]3
Trojan.Erotpics!sd6 [PC Tools]3
Trojan-Downloader.Win32.Exchanger.la [Kaspersky Lab]3
Generic PWS.ak [McAfee]2
TROJ_TIBS.QQ [Trend Micro]2
Trojan.Packed.NsAnti [Symantec]2
Trojan-Downloader.Win32.Exchanger.ahl [Kaspersky Lab]2
Trojan-Downloader.Win32.Exchanger.atl [Kaspersky Lab]2
Trojan-Downloader.Win32.Exchanger.qg [Kaspersky Lab]2
Backdoor.Trojan [Symantec]1
Backdoor:Win32/Olux.A [Microsoft]1
Downloader-BKH [McAfee]1
Exploit.AdobeReader [PC Tools]1
Infostealer.Gampass [Symantec]1
Mal/Generic-A [Sophos]1
Mal/TibsPak [Sophos]1
Mal/TibsPak, Mal/EncPk-DA [Sophos]1
PWS:Win32/Frethog.D [Microsoft]1
Troj/Agent-HTK [Sophos]1
Troj/Agent-HYD [Sophos]1
Troj/Cbeplay-A [Sophos]1
TROJ_AGENT.AWRZ [Trend Micro]1
TROJ_FAKEAV.CK [Trend Micro]1
TROJ_RENOS.AFD [Trend Micro]1
TROJ_TIBS.CLZ [Trend Micro]1
Trojan Horse [Symantec]1
Trojan.Pandex!sd6 [PC Tools]1
Trojan-Downloader.Exchanger [PC Tools]1
Trojan-Downloader.Win32.Exchanger.afh [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.ahf [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.anm [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.asd [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.aws [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.gc [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.hk [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.jt [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.ke [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.kt [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.ok [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.pn [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.pt [Kaspersky Lab]1
Trojan-Downloader.Win32.Exchanger.qc [Kaspersky Lab]1
TrojanDownloader:Win32/Cbeplay.I [Microsoft]1
Trojan-Spy.Gampass!sd6 [PC Tools]1
W32/Nuwar@MM [McAfee]1
Win32/Zhelatin.worm.78848.E [AhnLab]1
Win-Trojan/Exchanger.102626 [AhnLab]1
Win-Trojan/Exchanger.36752.B [AhnLab]1
Worm:Win32/Taterf.B [Microsoft]1

Trojan-Downloader.Win32.Exchanger [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation5

Trojan-Downloader.Win32.Exchanger [Ikarus] is known to be created as:
%System%\6to4svc32.dll
%System%\cbevtsvc.exe
%System%\ckvo.exe
%System%\kavo.exe
%Windir%\msauc.exe
c:\gx.com
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.