Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.InternetAntivirus [Ikarus]:

Trojan.Win32.InternetAntivirus [Ikarus] is also known as:
Threat AliasNumber of Incidents
Packed.Generic.200 [Symantec]67
Trojan:Win32/Alureon.gen!J [Microsoft]39
Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos]26
Trojan:Win32/InternetAntivirus [Microsoft]19
Rootkit.Win32.TDSS.eyj [Kaspersky Lab]18
Packed.Win32.Tdss.f [Kaspersky Lab]16
VirTool:Win32/Obfuscator.DQ [Microsoft]13
Trojan:Win32/Vundo.JC.dll [Microsoft]12
Generic FakeAlert.h [McAfee]10
Generic FakeAlert.k [McAfee]10
Packed.Win32.TDSS.y [Kaspersky Lab]10
Win-Trojan/Xema.variant [AhnLab]10
InternetAntivirus [Symantec]6
Mal/Generic-A [Sophos]6
Mal/TDSSPack-A [Sophos]6
Packed.Win32.Tdss.h [Kaspersky Lab]6
Trojan:Win32/Alureon.BH [Microsoft]6
Backdoor.Tidserv [Symantec]5
DNSChanger.r [McAfee]4
Mal/FakeVirPk-A [Sophos]4
Trojan:Win32/Alureon.gen!T [Microsoft]4
Mal/EncPk-GR, Mal/EncPk-GR [Sophos]3
Mal/FakeAV-M [Sophos]3
Mal/TDSSPack-Q [Sophos]3
Trojan.Win32.Tdss.alsw [Kaspersky Lab]3
TrojanDownloader:Win32/Rugzip.A [Microsoft]3
Adware.Lop [Symantec]2
FakeAlert-AB.gen.e [McAfee]2
FakeAlert-AB.gen.f [McAfee]2
FakeAlert-FQ [McAfee]2
Generic.dx [McAfee]2
Mal/FakeAV-BP [Sophos]2
Mal/TDSSPack-K [Sophos]2
Mal/TDSSPack-Q, Mal/TDSSPack-L, Mal/TDSSPack-K [Sophos]2
Mal/TDSSPack-R, Mal/EncPk-KG, Mal/TDSSPack-Q, Mal/TDSSPack-A [Sophos]2
Packed.Win32.TDSS.aa [Kaspersky Lab]2
RogueAntiSpyware.InternetAntiVirus [PC Tools]2
Rootkit.Win32.TDSS.ppb [Kaspersky Lab]2
Troj/Agent-JAD [Sophos]2
Trojan.Win32.TDSS.alpv [Kaspersky Lab]2
WindowsAntivirusPro [Symantec]2
Win-Trojan/Obfuscator.190976 [AhnLab]2
Adware.Lop [PC Tools]1
Backdoor.Tidserv!inf [Symantec]1
Backdoor.Win32.Inject.mw [Kaspersky Lab]1
Backdoor.Win32.TDSS.fp [Kaspersky Lab]1
DNSChanger.f.gen.a [McAfee]1
Downloader [Symantec]1
Downloader.MisleadApp [Symantec]1
Generic Downloader.j [McAfee]1
Generic FakeAlert!bo [McAfee]1
Mal/EncPk-CZ [Sophos]1
Mal/EncPk-HM, Mal/Packer [Sophos]1
Mal/EncPk-HT, Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]1
Mal/EncPk-KG, Mal/TDSSPack-A [Sophos]1
Mal/FakeAV-AD, Mal/TDSSPack-A, Mal/TDSSPack-E, Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos]1
Mal/FakeAV-BT, Mal/TDSSPack-Q [Sophos]1
Mal/TDSSPack-A, Mal/TDSSPack-R, Mal/TDSSPack-Q, Mal/EncPk-KG, Mal/EncPk-MX [Sophos]1
Mal/TDSSPack-E, Mal/TDSSPack-F, Mal/Alureon-C [Sophos]1
Mal/TDSSPack-J [Sophos]1
Mal/TDSSPack-R, Mal/EncPk-KG, Mal/TDSSPack-Q, Mal/TDSSPack-A, Mal/EncPk-HM [Sophos]1
Mal/UnkPack-Fam [Sophos]1
not-a-virus:FraudTool.Win32.InternetAntivirusPro.a [Kaspersky Lab]1
Packed.Win32.PePatch.kv [Kaspersky Lab]1
Packed.Win32.Tdss.c [Kaspersky Lab]1
Rootkit.TDSS!sd6 [PC Tools]1
Rootkit.Win32.TDSS.ctw [Kaspersky Lab]1
Rootkit.Win32.TDSS.dnn [Kaspersky Lab]1
Suspicious.MH690 [Symantec]1
Troj/Agent-JBL [Sophos]1
Trojan Horse [Symantec]1
Trojan.Win32.Agent2.dzl [Kaspersky Lab]1
Trojan.Win32.FakeAV.h [Kaspersky Lab]1
Trojan.Win32.Monder.gen [Kaspersky Lab]1
Trojan.Win32.TDSS.abeq [Kaspersky Lab]1
Trojan:Win32/Alureon [Microsoft]1
Trojan:Win32/Alureon.BJ [Microsoft]1
Trojan:Win32/FakeSpyguard [Microsoft]1
Trojan-Downloader.Win32.Agent.cngb [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.dsp [Kaspersky Lab]1
TrojanDropper:Win32/Natosen.A [Microsoft]1
TrojanSpy:Win32/Chadem.A [Microsoft]1
W32.Tidserv [Symantec]1
Win-Trojan/Downloader.40448.ED [AhnLab]1
Win-Trojan/Fraudload.47104.X [AhnLab]1
Win-Trojan/Fraudload.69637 [AhnLab]1
Win-Trojan/Tdss.32768 [AhnLab]1

Trojan.Win32.InternetAntivirus [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation7
Ukraine1

Trojan.Win32.InternetAntivirus [Ikarus] is known to be created as:
%CommonAppData%\microsoft\network\install.exe
%System%\senekabiysufkk.dll
%System%\senekapkrlnsyt.dll
%System%\senekapxywyksp.dll
%Temp%\file.exe
%Windir%\loadernew.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.