Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.FakeSmoke [Ikarus]:

Trojan.Win32.FakeSmoke [Ikarus] is also known as:
Threat AliasNumber of Incidents
Vundo.gen.bq [McAfee]226
Troj/Virtum-Gen [Sophos]217
Trojan.Vundo [Symantec]165
Worm:Win32/Vundo.B [Microsoft]148
Trojan:Win32/Vundo.FA [Microsoft]64
Trojan:Win32/FakeSmoke [Microsoft]24
Trojan:Win32/Vundo.gen!G [Microsoft]20
Trojan-Downloader.Win32.Agent.bqxc [Kaspersky Lab]19
Trojan-Clicker.Win32.Agent.ikc [Kaspersky Lab]9
WiniGuard [Symantec]9
Mal/Generic-A [Sophos]7
Mal/Generic-A, Troj/Virtum-Gen [Sophos]7
Mal/TDSSPack-A, Troj/Virtum-Gen [Sophos]7
Trojan-Dropper.Agent [Ikarus]7
Trojan.Win32.Buzus.bzdt [Kaspersky Lab]5
Packed.Win32.Krap.x [Kaspersky Lab]4
Trojan:Win32/FakeSpyguard [Microsoft]4
AntiVirus2008 [Symantec]2
FakeAlert-IT [McAfee]2
not-a-virus:FraudTool.Win32.WinBlueSoft.b [Kaspersky Lab]2
Packed.Win32.TDSS.aa [Kaspersky Lab]2
Trojan-Downloader.Win32.Agent.cklm [Kaspersky Lab]2
DNSChanger.r [McAfee]1
Downloader [Symantec]1
Mal/TDSSPack-A [Sophos]1
Mal/TDSSPack-Q, Mal/TDSSPack-A [Sophos]1
Mal/TDSSPack-Q, Troj/Virtum-Gen [Sophos]1
not-a-virus:AdWare.Win32.Virtumonde.balk [Kaspersky Lab]1
Packed.Generic.254 [Symantec]1
Trojan-Downloader.Agent.cklm [PC Tools]1
Win-Trojan/Agent.52224.NZ [AhnLab]1

Trojan.Win32.FakeSmoke [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Ukraine10
Japan5
Russian Federation4
China3

Trojan.Win32.FakeSmoke [Ikarus] is known to be created as:
%AllUsersProfile%\microsoft private data\microsoft\lan.dll
%CommonAppData%\microsoft\internet.dll
%ProgramFiles%\personal guard 2009\personalguard.exe
%ProgramFiles%\savekeep software\savekeep\savekeep.exe
%ProgramFiles%\savesoldier software\savesoldier\savesoldier.exe
%ProgramFiles%\systemcop software\systemcop\systemcop.exe
%ProgramFiles%\trustninja software\trustninja\trustninja.exe
%ProgramFiles%\trustninja software\trustninja\trustninjasvc.exe
%ProgramFiles%\winbluesoft software\winbluesoft\winbluesoft.exe
%ProgramFiles%\winifighter software\winifighter\winifighter.exe
%ProgramFiles%\winishield software\winishield\winishield.exe
%System%\5mcnt37d.exe
%System%\95i4eu6w.exe
%System%\dadiwewa.dll
%System%\gavapufa.dll
%System%\plq3uwkd.exe
%System%\vajetezo.dll
%Temp%\5mcnt37d.exe
%Temp%\95i4eu6w.exe
%Temp%\gpochvhmlg.dll
%Temp%\hwdgqmcw.exe
%Temp%\jodilose.dll
%Temp%\nonomaso.dll
%Temp%\pedetofo.dll
%Temp%\plq3uwkd.exe
%Temp%\rinokulo.dll
%Temp%\zavidegu.dll
%Temp%\zegofuho.dll
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).