Threat Search: 

ThreatExpert's Statistics for Trojan-Downloader.Win32.FakeRean [Ikarus]:

Trojan-Downloader.Win32.FakeRean [Ikarus] is also known as:
Threat AliasNumber of Incidents
TrojanDownloader:Win32/FakeRean [Microsoft]310
Packed.Generic.233 [Symantec]237
Mal/EncPk-IF [Sophos]175
FakeAlert-XPSecCenter [McAfee]169
TrojanDownloader:Win32/FakeRean.gen!C [Microsoft]120
Trojan.Win32.FraudPack.rcj [Kaspersky Lab]94
Trojan-Downloader.Win32.FraudLoad.fkv [Kaspersky Lab]60
Mal/Generic-A [Sophos]52
Downloader.MisleadApp [Symantec]51
Generic FakeAlert.d [McAfee]47
Mal/EncPk-EQ [Sophos]47
FakeAlert-DA [McAfee]43
Generic FakeAlert.d!gen [McAfee]35
Trojan-Downloader.Win32.FraudLoad.vdnu [Kaspersky Lab]24
Mal/EncPk-IV [Sophos]22
Trojan-Downloader.Win32.FraudLoad.eyw [Kaspersky Lab]21
Trojan.Virantix.C [Symantec]19
Generic Dropper.bu [McAfee]14
Win-Trojan/Fakealert.238642 [AhnLab]14
Downloader [Symantec]13
Downloader-BOI [McAfee]12
Troj/FakeVir-HR [Sophos]12
Mal/EncPk-KP [Sophos]11
Trojan-Downloader.Win32.FraudLoad.ehp [Kaspersky Lab]11
Trojan-Dropper.Win32.FrauDrop.hh [Kaspersky Lab]11
TrojanDropper:Win32/Olmarik.A [Microsoft]10
Olmarik [McAfee]9
Trojan.Fakeavalert [Symantec]9
Win-Trojan/Antiav.189791 [AhnLab]9
AntiVirus2009 [Symantec]8
Mal/EncPk-IV, Mal/EncPk-IF [Sophos]8
Trojan:Win32/FakeRean [Microsoft]8
Virus.Win32.Virut.au [Ikarus]8
Win-Trojan/Downloader.106499 [AhnLab]8
Trojan.Win32.FraudPack.uoe [Kaspersky Lab]6
Win-Trojan/FakeAv.189325 [AhnLab]6
Mal/EncPk-HH [Sophos]5
Trojan.Win32.FraudPack.qys [Kaspersky Lab]5
Trojan-Downloader.FraudLoad!sd6 [PC Tools]5
Trojan-Downloader.Win32.FraudLoad.eiq [Kaspersky Lab]5
Trojan-Downloader.Win32.FraudLoad.fdo [Kaspersky Lab]5
Win-Trojan/Downloader.104963 [AhnLab]5
Win-Trojan/Fakeav.190993.B [AhnLab]5
Win-Trojan/Fraudload.184393 [AhnLab]5
XPSecurityCenter [Symantec]5
FakeAlert-CM [McAfee]4
Mal/UnkPack-Fam [Sophos]4
Trojan.Win32.Pakes.lnh [Kaspersky Lab]4
Trojan:Win32/Ertfor.A [Microsoft]4
Trojan-Downloader.Win32.FraudLoad.vduc [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.tuun [Kaspersky Lab]4
Dropper/Agent.106499 [AhnLab]3
FakeAlert-FH [McAfee]3
FakeAlert-FH.dll [McAfee]3
Troj/FakeAl-J [Sophos]3
Trojan-Downloader.Win32.FraudLoad.fhe [Kaspersky Lab]3
Win-Trojan/Fakeav.190539 [AhnLab]3
Win-Trojan/FakeAV.346909 [AhnLab]3
Generic FakeAlert!co [McAfee]2
Mal/FakeAV-AD, Mal/EncPk-IF, Mal/EncPk-HH [Sophos]2
not-a-virus:FraudTool.Win32.AntiSpyWare2009.b [Kaspersky Lab]2
Troj/FakeAV-QB [Sophos]2
Troj/FakeAV-YF [Sophos]2
TROJ_INSEBRO.K [Trend Micro]2
Trojan.FakeAV [Symantec]2
Trojan.Virantix!sd6 [PC Tools]2
Trojan.Win32.Agent.cbiw [Kaspersky Lab]2
Trojan.Win32.FraudPack.pjv [Kaspersky Lab]2
Trojan-Downloader.Win32.FraudLoad.ezw [Kaspersky Lab]2
Trojan-Downloader.Win32.FraudLoad.fim [Kaspersky Lab]2
Trojan-Dropper.Win32.Agent.annd [Kaspersky Lab]2
Trojan-Dropper.Win32.FrauDrop.gs [Kaspersky Lab]2
Trojan-Ransom.Win32.FakeAV.aa [Kaspersky Lab]2
Win-Trojan/FakeRean.107523 [AhnLab]2
Win-Trojan/Xema.variant [AhnLab]2
AntiVirus2010 [Symantec]1
AntiVirusPro [Symantec]1
Backdoor.Trojan [Symantec]1
Backdoor.Win32.Hupigon.ewbc [Kaspersky Lab]1
Generic Downloader.x [McAfee]1
Generic Downloader.x!jm [McAfee]1
Generic FakeAlert.v [McAfee]1
Mal/EncPk-HH, Mal/FakeVirPk-A [Sophos]1
Mal/EncPk-IF, Mal/EncPk-HH [Sophos]1
Mal/FakeAV-AD [Sophos]1
Mal/FakeAV-AD, Mal/EncPk-IF, Mal/EncPk-HH, Mal/FakeVirPk-A [Sophos]1
not-a-virus:FraudTool.Win32.Agent.tm [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.Agent.tz [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.ab [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.br [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.bu [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.fb [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.fc [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.ff [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.fh [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.k [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.u [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntiSpyware2009.h [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPSecurityCenter.dj [Kaspersky Lab]1
Packed.Win32.Krap.t [Kaspersky Lab]1

Trojan-Downloader.Win32.FakeRean [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation111
Ukraine30

Trojan-Downloader.Win32.FakeRean [Ikarus] is known to be created as:
%AppData%\lizkavd.exe
%AppData%\seres.exe
%AppData%\svcst.exe
%ProgramFiles%\antispywarexp2009\uninstall.exe
%ProgramFiles%\antiviruspro_2010\antiviruspro_2010.exe
%ProgramFiles%\antiviruspro2009\uninstall.exe
%ProgramFiles%\xp_antispyware\uninstall.exe
%ProgramFiles%\xpprotectioncenter\uninstall.exe
%System%\jsne87fidgf.dll
%Temp%\msupd_2.exe
%Temp%\wini10491.exe
%Temp%\winlogin.exe
%Temp%\wisdstr.exe
%Windir%\sv.exe
%Windir%\svhoster.exe
%Windir%\svzip.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.