Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.FakeCog [Ikarus]:

Trojan.Win32.FakeCog [Ikarus] is also known as:
Threat AliasNumber of Incidents
Trojan:Win32/FakeCog [Microsoft]5
Mal/FakeAV-BP [Sophos]2
Mal/TDSSPack-R, Mal/EncPk-KG, Mal/TDSSPack-Q, Mal/TDSSPack-A [Sophos]2
Packed.Win32.TDSS.y [Kaspersky Lab]2
CoreGuardAntivirus2009 [Symantec]1
FakeAlert-CoreGuard [McAfee]1
FakeAlert-IR [McAfee]1
Mal/FakeVir-G [Sophos]1
Mal/Generic-A [Sophos]1
Mal/UnkPack-Fam [Sophos]1
not-a-virus:FraudTool.Win32.Agent.nn [Kaspersky Lab]1
Packed.Generic.200 [Symantec]1
Win-Trojan/Xema.variant [AhnLab]1

Trojan.Win32.FakeCog [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation1

Trojan.Win32.FakeCog [Ikarus] is known to be created as:
%AppData%\microsoft\windows\winlogon.exe
%ProgramFiles%\pc scout\coreext.dll
%System%\resdll.dll
%Temp%\wscsvc32.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).