Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.Meredrop [Ikarus]:

Trojan.Win32.Meredrop [Ikarus] is also known as:
Threat AliasNumber of Incidents
Trojan:Win32/Meredrop [Microsoft]60
Generic Dropper.bm [McAfee]52
Trojan.Skintrim [Symantec]50
Trojan-Dropper.Win32.Agent.zvf [Kaspersky Lab]49
TrojanDropper:Win32/Renos.K [Microsoft]48
Mal/Generic-A [Sophos]26
Packed/Upack [AhnLab]25
Trojan Horse [Symantec]20
New Malware.aj [McAfee]19
Generic Dropper [McAfee]17
Suspicious.MH690 [Symantec]16
Trojan.Dropper [Symantec]15
Generic.dx [McAfee]13
Mal/Emogen-E [Sophos]9
Mal/EncPk-HJ [Sophos]8
Troj/Dload-DU [Sophos]8
Mal/TibsPk-A [Sophos]6
Downloader [Symantec]4
Infostealer.Gampass [Symantec]4
Mal/Behav-160, Mal/Emogen-E [Sophos]4
Trojan.Win32.BHOLamp.fd [Kaspersky Lab]4
Trojan-Downloader.Win32.Agent.albp [Kaspersky Lab]4
Win-Trojan/OnlineGameHack.24064.DY [AhnLab]4
Downloader.gen.a [McAfee]3
Backdoor.Win32.Agent.ktz [Kaspersky Lab]2
Email-Worm.Joleee!sd6 [PC Tools]2
Email-Worm.Win32.Joleee.ap [Kaspersky Lab]2
Infostealer [Symantec]2
Mal/Dropper-O [Sophos]2
Mal/EncPk-GA [Sophos]2
Mal/Packer [Sophos]2
Troj/Agent-HVV [Sophos]2
Troj/Virtum-Gen [Sophos]2
Trojan.Fakeavalert [Symantec]2
Trojan.Vundo [Symantec]2
Trojan.Zlob [Symantec]2
TrojanDropper:Win32/Renos.Q [Microsoft]2
Vundo.gen.m [McAfee]2
Win-Trojan/Xema.variant [AhnLab]2
AntiVirus2009 [Symantec]1
Backdoor.Graybird [Symantec]1
Backdoor.Singu [Symantec]1
Backdoor.Win32.Agent.acrl [Kaspersky Lab]1
Backdoor.Win32.IRCBot.fgo [Kaspersky Lab]1
Backdoor.Win32.PcClient.nha [Kaspersky Lab]1
Constructor.Win32.FlyStudio.a [Kaspersky Lab]1
Downloader-ASH.gen.b [McAfee]1
Downloader-BLE [McAfee]1
Email-Worm.Win32.Joleee [Ikarus]1
Generic BackDoor [McAfee]1
Generic Dropper!bcv [McAfee]1
Generic Dropper!bei [McAfee]1
Generic Dropper.p [McAfee]1
Generic Exploit [McAfee]1
Generic PWS.y [McAfee]1
Generic.dx!hkg [McAfee]1
Infostealer.Banpaes.D [Symantec]1
Mal/Behav-009 [Sophos]1
Mal/Behav-043 [Sophos]1
Mal/Behav-116 [Sophos]1
Mal/Emogen-E, Mal/Behav-010, Mal/Behav-160 [Sophos]1
Mal/EncPk-AU [Sophos]1
Mal/EncPk-CR, Mal/Behav-164, Mal/TibsPak [Sophos]1
Mal/EncPk-FO, Mal/FakeVirPk-A [Sophos]1
Mal/EncPk-KF, Mal/TDSSPack-P [Sophos]1
Mal/FakeAV-BR [Sophos]1
Mal/FakeSpy-A [Sophos]1
Mal/Generic-A, Mal/Behav-053 [Sophos]1
Mal/PWS-Fam [Sophos]1
Mal/Sohana-A [Sophos]1
Mal/TibsPak [Sophos]1
Malware.Harakit [PC Tools]1
Malware.Pilleuz [PC Tools]1
Net-Worm.SillyFDC [PC Tools]1
New Win32.g4 [McAfee]1
not-a-virus:AdWare.Win32.E404.im [Kaspersky Lab]1
P2P-Worm.Win32.Nugg.ci [Kaspersky Lab]1
P2P-Worm.Win32.Palevo.kje [Kaspersky Lab]1
Packed.Generic.238 [Symantec]1
Packed.Generic.80 [Symantec]1
Puper [McAfee]1
PWS-OnlineGames.as [McAfee]1
RogueAntiSpyware.AntiVirus2009 [PC Tools]1
Troj/Agent-LSU [Sophos]1
Troj/BadCab-A [Sophos]1
Troj/Dropr-K [Sophos]1
Troj/Merein-Gen [Sophos]1
TROJ_PACKED.BQV [Trend Micro]1
TROJ_VUNDO.ACM [Trend Micro]1
Trojan.Adclicker [Symantec]1
Trojan.Agent.ESOQ [PC Tools]1
Trojan.Generic [PC Tools]1
Trojan.Pandex [Symantec]1
Trojan.Pandex!sd6 [PC Tools]1
Trojan.QQHelper.Gen [PC Tools]1
Trojan.Win32.Agent.agop [Kaspersky Lab]1
Trojan.Win32.Agent.agvo [Kaspersky Lab]1
Trojan.Win32.Agent.agzg [Kaspersky Lab]1
Trojan.Win32.Agent.ahkr [Kaspersky Lab]1
Trojan.Win32.Agent.ahle [Kaspersky Lab]1

Trojan.Win32.Meredrop [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China23
Russian Federation15
United Kingdom3
Spain2
Germany1
Israel1
Saudi Arabia1
Slovenia1
Sweden1
Switzerland1

Trojan.Win32.Meredrop [Ikarus] is known to be created as:
%AppData%\onload.exe
%ProgramFiles%\common files\system\qqlzul.exe
%ProgramFiles%\ssc service utility\uninst.exe
%System%\cssrss.exe
%System%\dllcache\userinit.exe
%System%\glu3232.dll
%System%\scvhost.exe
%System%\sdra64.exe
%System%\userload.exe
%System%\wuaucit.exe
%Temp%\21.exe
%Temp%\ixp000.tmp\keygen.exe
%Temp%\kafan virlist 2009.04.07\090407-5-4.exe
%Windir%\9129837.exe
%Windir%\ky0vr.exe
%Windir%\scvhost.exe
%Windir%\services.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.