Threat Search: 

ThreatExpert's Statistics for Trojan-Spy.Agent!sd5 [PC Tools]:

Trojan-Spy.Agent!sd5 [PC Tools] is also known as:
Threat AliasNumber of Incidents
Generic PWS [McAfee]106
Trojan-Spy.Win32.Agent.qj [Kaspersky Lab]92
TROJ_MNLESS.AH [Trend Micro]56
Trojan Horse [Symantec]53
W32.Xema.A [Symantec]50
Troj/Agent-FXF [Sophos]49
Trojan-Spy.Win32.Agent.qj [Ikarus]35
Infostealer [Symantec]32
Bloodhound.Unknown [Symantec]14
Win-Trojan/Xema.variant [AhnLab]14
Generic PWS.y [McAfee]11
Generic.cd [McAfee]11
Trojan-Spy.Win32.Agent.et [Kaspersky Lab]9
Trojan:Win32/Jenix!rts [Microsoft]7
Trojan-Spy.Win32.Agent.iw [Kaspersky Lab]7
SearchNet [McAfee]6
Trojan-Spy.Win32.Agent.bqf [Kaspersky Lab]6
Trojan-Spy.Win32.Agent.nu [Kaspersky Lab]6
TROJ_AGENT.S [Trend Micro]5
Trojan-Spy.Win32.Agent.ha [Kaspersky Lab]5
Trojan-Spy.Win32.Agent.lt [Kaspersky Lab]5
Trojan-Spy.Win32.Agent.s [Kaspersky Lab]5
Backdoor.Trojan [Symantec]4
Downloader.Trojan [Symantec]4
PWS-FFantasy.dr [McAfee]4
PWS-IT [McAfee]4
PWS-IT.kit [McAfee]4
Spy-Agent.bj [McAfee]4
TROJ_AGENT.CLI [Trend Micro]4
TROJ_Generic [Trend Micro]4
Trojan.Finfanse [Symantec]4
Trojan-Spy.Win32.Agent.nq [Kaspersky Lab]4
TSPY_AGENT.ASV [Trend Micro]4
TSPY_AGENT.DBV [Trend Micro]4
W32/Lewor.gen [McAfee]4
Adware.PigSearch [Symantec]3
New Malware.aj [McAfee]3
TROJ_AGENT.T [Trend Micro]3
Trojan-Spy.BAT.Agent.a [Kaspersky Lab]3
Trojan-Spy.Win32.Agent.pn [Kaspersky Lab]3
Trojan-Spy.Win32.Agent.t [Kaspersky Lab]3
TSPY_AGENT.DJV [Trend Micro]3
W32.Hitapop [Symantec]3
Backdoor.Formador [Symantec]2
BKDR_MUHARAM.B [Trend Micro]2
Generic PWS.af [McAfee]2
Generic PWS.r [McAfee]2
Generic.dc [McAfee]2
Hacktool [Symantec]2
Spy-Agent.br.dll [McAfee]2
TROJ_AGENT.BZX [Trend Micro]2
Trojan-Spy.Win32.Agent.ajb [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.bwu [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.bwx [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.ccs [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.fj [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.hh [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.ir [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.ni [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.pi [Kaspersky Lab]2
TSPY_AGENT.ADJM [Trend Micro]2
TSPY_AGENT.LVA [Trend Micro]2
Adware.AllSum [Symantec]1
Allsum [McAfee]1
Backdoor.Bifrose [Symantec]1
BackDoor-BAE.dll [McAfee]1
BackDoor-CAY [McAfee]1
BackDoor-CEP.svr [McAfee]1
BackDoor-CGX.svr [McAfee]1
BackDoor-CHN.gen [McAfee]1
BackDoor-CKB.dr [McAfee]1
BackDoor-TW [McAfee]1
BKDR_BIFROSE.A [Trend Micro]1
BKDR_BLKHOLE.A [Trend Micro]1
BKDR_PRORAT.17 [Trend Micro]1
Downloader-AYF [McAfee]1
Enfal [McAfee]1
Generic BackDoor.d [McAfee]1
Generic BackDoor.t [McAfee]1
Generic Delphi [McAfee]1
Generic Downloader.ak [McAfee]1
Generic PUP.g [McAfee]1
Generic PWS.b [McAfee]1
Generic PWS.n [McAfee]1
Generic.b [McAfee]1
Generic.ca [McAfee]1
Generic.di [McAfee]1
Generic.dk [McAfee]1
Generic.du [McAfee]1
Generic.dx [McAfee]1
Generic.fc [McAfee]1
Hacktool.PassReminder [Symantec]1
Infostealer.Bancos [Symantec]1
Infostealer.Bancos!gen [Symantec]1
Infostealer.Bancos.Z [Symantec]1
Infostealer.Gampass [Symantec]1
Infostealer.Goldpay [Symantec]1
Infostealer.Revcuss.A [Symantec]1
KeyHook.dll [McAfee]1
Keylog-Khlog [McAfee]1

Trojan-Spy.Agent!sd5 [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
China18
Brazil3
France1
Russian Federation1
Sweden1
Taiwan1
Turkey1
United Kingdom1

Trojan-Spy.Agent!sd5 [PC Tools] is known to be created as:
%ProgramFiles%\internet explorer\update.dll
%ProgramFiles%\searchnet\searchnet.exe
%ProgramFiles%\searchnet\servehost.exe
%ProgramFiles%\searchnet\serveup.exe
%ProgramFiles%\searchnet\srvnet32.dll
%System%\16721.dll
%System%\22.dll
%System%\abrada.exe
%System%\almjdll.dll
%System%\alxres070417.exe
%System%\chkdisk.exe
%System%\d934400.dll
%System%\explorer.dll
%System%\hatama.dll
%System%\id1esvc.exe
%System%\idlesvc.exe
%System%\inetcpl.exe
%System%\inter32.dll
%System%\jxkey.dll
%System%\kernl32.exe
%System%\mailman.exe
%System%\mpd.dll
%System%\msdivprt.exe
%System%\msdtcprt.dll
%System%\msn.exe
%System%\msoffice.dll
%System%\mspeupx.exe
%System%\msvchost.exe
%System%\nnview.dll
%System%\nvapp32.dll
%System%\qqbus.exe
%System%\ravcopy.exe
%System%\scrsys070417.scr
%System%\scrsys16_061230.scr
%System%\scrsys16_070417.scr
%System%\servehost.exe
%System%\servicess.exe
%System%\shellext\explorer.exe
%System%\sivchost.exe
%System%\skl1.0.exe
%System%\spoolsv\spoolsv.exe
%System%\ssvchost.com
%System%\sysdchp.exe
%System%\tmhk.dll
%System%\toto.dll
%System%\tqqbus.exe
%System%\uqqbus.dll
%System%\usrsvc.exe
%System%\winlogin.exe
%System%\winmsic.exe
%System%\winsvcc.exe
%System%\winsys16_061230.dll
%System%\winsys16_070417.dll
%System%\winusb.exe
%System%\wnilogon.exe
%System%\xktxx.exe
%Temp%\4679b317.exe
%Temp%\57ede603.dll
%Temp%\9ddbd92d.exe
%Temp%\abs.exe
%Temp%\b80114b0.exe
%Temp%\msdivprt.exe
%Temp%\msdtcprt.dll
%Temp%\skleditor1.0.exe
%Windir%\bsr.exe
%Windir%\cmd.dll
%Windir%\iexpl0re.exe
%Windir%\svchost.exe
%Windir%\system\bremct32.dll
%Windir%\usrexplore.exe
c:\bsr.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.