Threat Search: 

ThreatExpert's Statistics for Trojan-Dropper.Win32.Agent.vsl [Kaspersky Lab]:

Trojan-Dropper.Win32.Agent.vsl [Kaspersky Lab] is also known as:
Threat AliasNumber of Incidents
Hacktool.Rootkit [Symantec]4
Mal/EncPk-CK [Sophos]4
TROJ_DROPPER.GXU [Trend Micro]4
Trojan.Dropper [Symantec]4
Trojan.Srizbi [PC Tools]4
TrojanDropper:Win32/Srizbi.gen!D [Microsoft]4
Generic FakeAlert.a [McAfee]2
Hacktool.Rootkit!sd6 [PC Tools]2
Mal/Generic-A [Sophos]2
Spammer:WinNT/Srizbi.B [Microsoft]2
Spammer:WinNT/Srizbi.gen!B [Microsoft]2
Srizbi [McAfee]2
TROJ_DROPPER.GEE [Trend Micro]2

Trojan-Dropper.Win32.Agent.vsl [Kaspersky Lab] is known to be created as:
%System%\drivers\rovpvsrn.sys
%System%\drivers\rrvvnnrr.sys
%System%\drivers\rtxvjplv.sys
%System%\drivers\suqnqtuo.sys
%Temp%\inst1_294.exe
%Windir%\jbqjbkjr.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.