Threat Search: 

ThreatExpert's Statistics for Trojan.SpamThru [PC Tools]:

Trojan.SpamThru [PC Tools] is also known as:
Threat AliasNumber of Incidents
Downloader [Symantec]30
Trojan.Win32.Qhost [Ikarus]24
Trojan.Win32.Qhost.mlv [Kaspersky Lab]23
Downloader.gen.a [McAfee]21
Win-Trojan/Qhost.2048 [AhnLab]21
Generic Qhost!y [McAfee]20
Mal/Generic-A [Sophos]19
Downloader-BAC [McAfee]17
TROJ_DLOADER.BG [Trend Micro]16
TROJ_DLOADER.CO [Trend Micro]16
Trojan.SpamThru [Symantec]16
Trojan-Downloader.Win32.Small.hko [Kaspersky Lab]16
TROJ_SPAMBOT.B [Trend Micro]14
Trojan:Win32/Koobface.B [Microsoft]14
Backdoor.Win32.Agent.adr [Kaspersky Lab]11
TROJ_DLOADER.WTG [Trend Micro]6
Trojan-Downloader.Win32.Small.ddx [Kaspersky Lab]6
Trojan-Downloader.Win32.Small.fyx [Kaspersky Lab]6
TROJ_SMALL.BKJ [Trend Micro]4
TROJ_SMALL.IRN [Trend Micro]4
Trojan.PWS.QQPass [Symantec]4
Trojan-Downloader.Win32.Small.gdy [Kaspersky Lab]4
Trojan.Peacomm [Symantec]3
Backdoor.Trojan [Symantec]2
Generic.dx [McAfee]2
Mal/Behav-316 [Sophos]2
Mal/SpamThru-A, Troj/SpamTh-Gen [Sophos]2
Spy-Agent.dy [McAfee]2
TROJ_DLOADER.QIV [Trend Micro]2
TROJ_DLOADER.STI [Trend Micro]2
TROJ_DLOADER.WTI [Trend Micro]2
Trojan.Win32.Qhost.aru [Kaspersky Lab]2
Trojan:Win32/SpamThru.gen!dll [Microsoft]2
Trojan-Downloader.Win32.Small.hcm [Kaspersky Lab]2
Backdoor.Win32.Agent.ail [Kaspersky Lab]1
Backdoor.Win32.Agent.uu [Kaspersky Lab]1
Backdoor.Win32.Bredavi.azn [Kaspersky Lab]1
Dropper/Xema.67584.H [AhnLab]1
Generic BackDoor.m [McAfee]1
Generic Downloader [McAfee]1
Generic Downloader.z [McAfee]1
Infostealer [Symantec]1
Packed.Win32.TDSS.z [Kaspersky Lab]1
TROJ_DLOADER.DUF [Trend Micro]1
TROJ_Generic [Trend Micro]1
TROJ_SMALL.IRO [Trend Micro]1
TROJ_SMALL.IZU [Trend Micro]1
Trojan.Adclicker [Symantec]1
Trojan.Generic [Ikarus]1
Trojan.Win32.Qhost.it [Kaspersky Lab]1
Trojan-Downloader.Win32.Bensorty.r [Kaspersky Lab]1
TSPY_AGENT.IRZ [Trend Micro]1
Virus.Win32.Virut.ce [Kaspersky Lab]1
Win-Trojan/Agent.184864 [AhnLab]1
Win-Trojan/Agent.184864.B [AhnLab]1

Trojan.SpamThru [PC Tools] has the following possible country of origin:
OriginNumber of Incidents
Switzerland1

Trojan.SpamThru [PC Tools] is known to be created as:
%System%\d4ghggf4g.dll
%System%\dhgthfg.dll
%System%\drls.dll
%System%\frjkfl4g.dll
%System%\fsd9mk4g.dll
%System%\h4dj24g.dll
%System%\hfdj84g.dll
%System%\hfjd94d.dll
%System%\hfkr4g.dll
%System%\hjd94fg.dll
%System%\j8dj3jg.dll
%System%\jfs9jg.dll
%System%\jkd845jg.dll
%System%\kf93jfg.dll
%System%\kf9467g.dll
%System%\kf94lfg.dll
%System%\ldhje783.dll
%System%\lfj95jg.dll
%System%\mdf90kdf.dll
%System%\qasfe.dll
%System%\s7dsf4g.dll
%System%\zkpecrypt.dll
%Temp%\hosts2.exe
%Temp%\zpskon_1264169224.exe
%Temp%\zpskon_1264253259.exe
%Temp%\zpskon_1264459759.exe
%Temp%\zpskon_1264541897.exe
%Temp%\zpskon_1264665884.exe
%Temp%\zpskon_1264798279.exe
%Temp%\zpskon_1264868541.exe
%Temp%\zpskon_1264869251.exe
%Temp%\zpskon_1264869302.exe
%Temp%\zpskon_1265037188.exe
%Temp%\zpskon_1265508832.exe
%Temp%\zpskon_1265596753.exe
%Temp%\zpskon_1265674902.exe
%Temp%\zpskon_1265675642.exe
%Temp%\zpskon_1265678858.exe
%Temp%\zpskon_1265791546.exe
%Temp%\zpskon_1265835021.exe
%Temp%\zpskon_1265863458.exe
%Temp%\zpskon_1266026778.exe
%Temp%\zpskon_1266027604.exe
%Temp%\zpskon_1266028111.exe
%Temp%\zpskon_1266286395.exe
%Temp%\zpskon_1266440304.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).