Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.FraudPack [Ikarus]:

Trojan.Win32.FraudPack [Ikarus] is also known as:
Threat AliasNumber of Incidents
Mal/EncPk-CZ [Sophos]143
Downloader [Symantec]138
Generic Dropper.cx [McAfee]131
Trojan.Win32.FraudPack.aoy [Kaspersky Lab]121
Trojan Horse [Symantec]114
Mal/Generic-A [Sophos]73
Trojan.FraudPack!sd6 [PC Tools]61
Generic Dropper.bw [McAfee]55
Trojan.Win32.FraudPack.pmy [Kaspersky Lab]37
Troj/FakeVir-KH [Sophos]33
Trojan.Win32.FraudPack.gen [Kaspersky Lab]32
Trojan.Win32.FraudPack.vds [Kaspersky Lab]30
FakeAlert-DZ [McAfee]29
Packed.Generic.187 [Symantec]28
Mal/FakeAV-AD [Sophos]27
Trojan:Win32/Winwebsec [Microsoft]23
SpywareProtect2009 [Symantec]22
TrojanDownloader:Win32/Renos [Microsoft]20
Trojan.Fakeavalert [Symantec]18
Trojan.Win32.FraudPack.gxo [Kaspersky Lab]18
Downloader-BKT [McAfee]12
Generic.dx [McAfee]12
Win-Trojan/Downloader.27136.DL [AhnLab]12
Generic Downloader.x [McAfee]9
Trojan.Win32.FraudPack.any [Kaspersky Lab]9
Trojan:Win32/FakeXPA [Microsoft]9
FakeAlert-C.dr [McAfee]8
Mal/EncPk-HW [Sophos]8
Mal/FakeVirPk-A [Sophos]8
Troj/FakeAle-MC [Sophos]8
TrojanDownloader:Win32/FakeRean [Microsoft]8
AntiVirus2009 [Symantec]7
FakeAlert-EL [McAfee]7
Mal/EncPk-JD [Sophos]7
Mal/TibsPk-A, Mal/EncPk-CZ [Sophos]7
Trojan.Win32.FraudPack.pre [Kaspersky Lab]7
Trojan.Win32.FraudPack.tnb [Kaspersky Lab]7
Win-Trojan/Fraudpack.143368 [AhnLab]7
AntiVirus2008 [Symantec]6
FakeAlert-R [McAfee]6
Generic.dx!bew [McAfee]6
Mal/EncPk-IF [Sophos]6
Troj/FakeAV-HE [Sophos]6
TrojanDownloader:Win32/Renos.DY [Microsoft]6
FakeAlert-EQ [McAfee]5
Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos]5
RogueAntiSpyware.AntiVirusPro [PC Tools]5
Trojan.Win32.FraudPack.amm [Kaspersky Lab]5
Trojan.Win32.FraudPack.iph [Kaspersky Lab]5
Trojan:Win32/Liften.B [Microsoft]5
TrojanDownloader:Win32/Renos.GW [Microsoft]5
Win-Trojan/Xema.variant [AhnLab]5
Awola [Symantec]4
Generic PUP.x [McAfee]4
Infostealer [Symantec]4
Mal/FakeAV-I, Mal/EncPk-CZ [Sophos]4
Suspicious.Vundo [Symantec]4
Troj/FakeRean-E [Sophos]4
Trojan.Win32.FraudPack.ase [Kaspersky Lab]4
Trojan.Win32.FraudPack.gjt [Kaspersky Lab]4
Trojan.Win32.FraudPack.ipf [Kaspersky Lab]4
Trojan.Win32.FraudPack.psk [Kaspersky Lab]4
Trojan.Win32.FraudPack.qdp [Kaspersky Lab]4
Trojan.Win32.FraudPack.udx [Kaspersky Lab]4
Trojan.Win32.FraudPack.vir [Kaspersky Lab]4
Trojan.Zlob [Symantec]4
Win-Trojan/Fraudpack.114688.K [AhnLab]4
Win-Trojan/Fraudpack.143364.B [AhnLab]4
Generic FakeAlert.n [McAfee]3
Infostealer.Banker.C [Symantec]3
InternetAntivirus [Symantec]3
Mal/Behav-321, Mal/EncPk-FO, Mal/FakeVirPk-A [Sophos]3
Mal/EncPk-FX [Sophos]3
Mal/EncPk-II [Sophos]3
Mal/EncPk-JY [Sophos]3
Mal/FakeAV-I [Sophos]3
Mal/WaledPak-D [Sophos]3
Packed.Win32.Katusha.a [Kaspersky Lab]3
PWS:Win32/Zbot.gen!B [Microsoft]3
Suspicious.Vundo.2 [Symantec]3
Trojan.FraudPack.ANY [PC Tools]3
Trojan.Win32.FraudPack.pkb [Kaspersky Lab]3
Trojan.Win32.FraudPack.qaw [Kaspersky Lab]3
Win-Trojan/Fakeav.51712 [AhnLab]3
Downloader.MisleadApp [Symantec]2
FakeAlert-AB [McAfee]2
Mal/EncPk-CZ, Mal/EncPk-EI [Sophos]2
Mal/EncPk-HW, Mal/EncPk-JD [Sophos]2
Mal/FakeAV-AM [Sophos]2
Mal/FakeAV-M [Sophos]2
PerfectDefender2009 [Symantec]2
PWS:Win32/Zbot.VA [Microsoft]2
SpywareGuard2008 [Symantec]2
Troj/FakeAV-GR [Sophos]2
TROJ_FAKEAV.AJY [Trend Micro]2
Trojan.FakeAV [Symantec]2
Trojan.Fakeavalert.B [Symantec]2
Trojan.Win32.FraudPack.apv [Kaspersky Lab]2
Trojan.Win32.FraudPack.aqb [Kaspersky Lab]2
Trojan.Win32.FraudPack.kfe [Kaspersky Lab]2

Trojan.Win32.FraudPack [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation59
Ukraine4
China3
Netherlands3
Spain1

Trojan.Win32.FraudPack [Ikarus] is known to be created as:
%AppData%\0671592029\0671592029.exe
%AppData%\2354047482\2354047482.exe
%AppData%\9790278843\9790278843.exe
%AppData%\lizkavd.exe
%CommonAppData%\11312964\11312964.exe
%CommonAppData%\2deb8\wi064.exe
%ProgramFiles%\antiviruspro_2010\antiviruspro_2010.exe
%ProgramFiles%\antiviruspro_2010\uninstall.exe
%ProgramFiles%\computer defender 2009\cd2009.exe
%ProgramFiles%\malwareremoval\malwareremoval.exe
%ProgramFiles%\proof defender 2009\pdfndr.exe
%ProgramFiles%\vkeytx\iuxqsysguard.exe
%ProgramFiles%\vrl32software\vrl32.exe
%System%\090520-a-7.exe
%System%\avcorefn.dll
%System%\core.dll
%System%\css2_32.dll
%System%\frmwrk32.exe
%System%\iebho.dll
%System%\iehelper.dll
%System%\lphc35dj0erc1.exe
%System%\minix32.exe
%System%\mkrnl.exe
%System%\msupdate.exe
%System%\msxml71.dll
%System%\netfilter.exe
%System%\setupmalwareremoval.exe
%System%\sysfldr.dll
%System%\twext.exe
%System%\xppolice.exe
%Temp%\090520-a-7.exe
%Temp%\1_dropper_other.exe
%Temp%\3919597899.exe
%Temp%\a.exe
%Temp%\b.exe
%Temp%\c.exe
%Temp%\d.exe
%Temp%\e.exe
%Temp%\f.exe
%Temp%\g.exe
%Temp%\i.exe
%Temp%\kafan virlist 20090715\090714-7-8.exe
%Temp%\msa.exe
%Temp%\msb.exe
%Temp%\msxml71.dll
%Temp%\nss2.tmp\db.exe
%Temp%\svchost.exe
%Windir%\file.exe
%Windir%\msa.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.