Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.VB [Ikarus]:

Trojan.Win32.VB [Ikarus] is also known as:
Threat AliasNumber of Incidents
Trojan Horse [Symantec]555
INF.Autorun.Gen [PC Tools]403
Trojan.Win32.VB.bmr [Kaspersky Lab]288
Win-Trojan/Xema.variant [AhnLab]215
Mal/Generic-A [Sophos]205
Trojan.Win32.VB.ezu [Kaspersky Lab]192
Win-Trojan/Dbi.46615 [AhnLab]192
Worm:Win32/Autorun.XFV [Microsoft]192
Troj/VBDrpB-Gen [Sophos]188
Generic.dx [McAfee]173
Trojan.VB!sd6 [PC Tools]139
Generic VB.c [McAfee]93
Trojan.VB.EZU [PC Tools]90
Trojan:Win32/VB [Microsoft]74
Trojan.Win32.VB.goe [Kaspersky Lab]72
Backdoor.Trojan [Symantec]54
Downloader [Symantec]54
W32.Pagipef.B [Symantec]52
TROJ_PAGIPEF.R [Trend Micro]51
W32.SillyFDC [Symantec]48
Troj/Alllu-A [Sophos]44
Generic VB.b [McAfee]43
Trojan.Win32.VB.aia [Kaspersky Lab]42
Trojan:Win32/Provis!rts [Microsoft]39
Possible_VBM [Trend Micro]33
Virus.Win32.Small.p [Kaspersky Lab]27
Mal/Generic-E [Sophos]26
Virus:Win32/Sality.AM [Microsoft]26
Mal/Bimay-A [Sophos]25
Mal/EncPk-C [Sophos]25
Trojan.Win32.VB.idf [Kaspersky Lab]24
Trojan.VB!sd5 [PC Tools]23
Trojan:Win32/Meredrop [Microsoft]23
Worm:Win32/Hamweq.W [Microsoft]23
Mal/VB-AB [Sophos]22
W32/Sality-AM [Sophos]22
Generic AdClicker.p [McAfee]21
Packed/FSG [PC Tools]21
Mal/TibsPk-A [Sophos]18
Trojan.Adclicker [Symantec]18
Trojan.Generic [PC Tools]18
Trojan.Win32.VB.boz [Kaspersky Lab]17
Trojan.Win32.VB.cpa [Kaspersky Lab]17
Trojan.Win32.VB.ndy [Kaspersky Lab]17
Trojan.Win32.VB.dcw [Kaspersky Lab]16
Virus.Win32.Xorer.bh [Kaspersky Lab]16
W32/Autorun.worm.i.gen [McAfee]16
W32/SillyFDC-CT [Sophos]16
Win-Trojan/Agent.40960.VA [AhnLab]16
Mal/VBDos-A [Sophos]15
Packed/Upack [AhnLab]15
TROJ_VB.GFG [Trend Micro]15
VirTool:Win32/VBInject.gen!AN [Microsoft]15
W32/Sality.gen [McAfee]15
Virus.Win32.Texel.a [Kaspersky Lab]13
W32.Sality.AE [Symantec]13
Generic BackDoor [McAfee]12
Trojan.Win32.Clicker.a [Kaspersky Lab]12
Trojan-PWS.Hazif [PC Tools]12
Virus.Win32.Sality.aa [Kaspersky Lab]12
Worm.AutoRun.WHY [PC Tools]12
Worm:Win32/Autorun.FO [Microsoft]12
WORM_VB.ERF [Trend Micro]12
Infostealer.Gampass [Symantec]11
Trojan.Win32.VB.nwd [Kaspersky Lab]11
Trojan.Win32.VB.uqe [Kaspersky Lab]11
TrojanDropper:Win32/VB.AG [Microsoft]11
W32/Autorun-DP [Sophos]11
Mal/Packer [Sophos]10
Refpron.gen [McAfee]10
Trojan.Win32.VB.bcg [Kaspersky Lab]10
Trojan.Win32.VB.jvc [Kaspersky Lab]10
Trojan.Win32.VB.ujq [Kaspersky Lab]10
Trojan:Win32/Gontu.B!dll [Microsoft]10
Generic.dx!l [McAfee]9
Infostealer [Symantec]9
Mal/VB-F [Sophos]9
Suspicious.MH690 [Symantec]9
Troj/Refpron-K [Sophos]9
Trojan.VB.EHF [PC Tools]9
Trojan.VB.FSQ [PC Tools]9
Trojan.Win32.VB.aqt [Kaspersky Lab]9
Trojan.Win32.VB.avf [Kaspersky Lab]9
Trojan.Win32.VB.hnt [Kaspersky Lab]9
Trojan.Win32.VB.vcu [Kaspersky Lab]9
VirTool:Win32/VBInject.AQ [Microsoft]9
W32.IRCBot [Symantec]9
W32.SillyDC [Symantec]9
W32/USBAgent [McAfee]9
WORM_VB.BDN [Trend Micro]9
Generic Downloader.x [McAfee]8
Infostealer.QQRob.A [Symantec]8
Mal/VBWorm-C, Mal/Emogen-F [Sophos]8
Troj/VB-EGN [Sophos]8
Trojan.Win32.VB.uc [Kaspersky Lab]8
Trojan:Win32/Comame [Microsoft]8
TSPY_HAZIF.A [Trend Micro]8
Virus.Win32.Texel.i [Kaspersky Lab]8
Virus:Win32/Virut.BM [Microsoft]8
W32.Dizan [Symantec]8

Trojan.Win32.VB [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China149
Germany44
Spain42
Turkey15
Japan14
Brazil12
Saudi Arabia12
Morocco9
Republic of Korea4
Italy3
Russian Federation3
Sweden3
Taiwan3
United Kingdom3
France2
Iran2
Israel2
Belgium1
Croatia1
Egypt1
Finland1
Netherlands1
Romania1
Ukraine1

Trojan.Win32.VB [Ikarus] is known to be created as:
%AllUsersProfile%\desktop.exe
%AllUsersProfile%\documents.exe
%AllUsersProfile%\drm.exe
%AllUsersProfile%\drm\drm.exe
%AllUsersProfile%\favorites.exe
%AllUsersProfile%\templates.exe
%AppData%\%username%.task\services.exe
%AppData%\explorer.exe
%AppData%\lsass.exe
%AppData%\microsoft\svchost.exe
%AppData%\svchost.exe
%AppData%\winupdate.exe
%CommonAppData%\adobe.exe
%CommonAppData%\adobe\adobe.exe
%CommonAppData%\microsoft.exe
%CommonAppData%\microsoft\crypto.exe
%CommonAppData%\microsoft\crypto\crypto.exe
%CommonAppData%\microsoft\crypto\dss.exe
%CommonAppData%\microsoft\crypto\dss\dss.exe
%CommonAppData%\microsoft\crypto\rsa.exe
%CommonAppData%\microsoft\crypto\rsa\rsa.exe
%CommonAppData%\microsoft\microsoft.exe
%CommonAppData%\microsoft\network.exe
%CommonAppData%\microsoft\network\connections.exe
%CommonAppData%\microsoft\network\connections\connections.exe
%CommonAppData%\microsoft\network\network.exe
%CommonAppData%\normal.exe
%CommonAppData%\vmware.exe
%CommonDesktopDir%\desktop.exe
%CommonDocuments%\documents.exe
%CommonFavorites%\favorites.exe
%CommonPrograms%\startup\msadvisor.exe
%CommonPrograms%\startup\sysinfo.exe
%CommonTemplates%\templates.exe
%DesktopDir%\desktop.exe
%DesktopDir%\winupdaterwinnt.exe
%Favorites%\favorites.exe
%FontsDir%\uucmss.exe
%MyDocuments%\dlhost.exe
%MyDocuments%\explorer.exe
%Profiles%\default user\cookies.exe
%Profiles%\default user\desktop.exe
%Profiles%\default user\desktop\desktop.exe
%Profiles%\default user\favorites.exe
%Profiles%\default user\favorites\favorites.exe
%Profiles%\default user\nethood.exe
%Profiles%\default user\nethood\nethood.exe
%Profiles%\default user\printhood.exe
%Profiles%\default user\printhood\printhood.exe
%Profiles%\default user\recent.exe
%Profiles%\default user\recent\recent.exe
%Profiles%\default user\sendto.exe
%Profiles%\default user\sendto\sendto.exe
%Profiles%\default user\templates.exe
%Profiles%\default user\templates\templates.exe
%Profiles%\default user\templates\winword.doc.exe
%Profiles%\default user\templates\winword.exe
%Profiles%\default user\templates\winword2.doc.exe
%Profiles%\default user\templates\winword2.exe
%Profiles%\localservice.exe
%Profiles%\localservice\cookies.exe
%Profiles%\localservice\localservice.exe
%Profiles%\networkservice.exe
%Profiles%\networkservice\cookies.exe
%Profiles%\networkservice\networkservice.exe
%ProgramFiles%\aore-unpacktools\armadumper.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\svchost32.exe
%ProgramFiles%\crux calculator v5\crux_calc.exe
%ProgramFiles%\explorer.exe
%ProgramFiles%\internet explorer\connection wizard\explorer.exe
%ProgramFiles%\internet explorer\mui\winmon.exe
%ProgramFiles%\internet explorer\smss.exe
%ProgramFiles%\kindar\kindar.exe
%ProgramFiles%\msn\msn9.exe
%ProgramFiles%\mui\microsoftms.exe
%ProgramFiles%\mui\sysmss.exe
%ProgramFiles%\snx.exe
%ProgramFiles%\tn_hacker\tn_hacker.exe
%ProgramFiles%\uninst.exe
%ProgramFiles%\windowsupdate\imjpmig.exe
%ProgramFiles%\winmon.exe
%Programs%\startup\1a353.exe.exe
%Programs%\startup\377f7.exe.exe
%Programs%\startup\3852b.exe.exe
%Programs%\startup\51059.exe.exe
%Programs%\startup\6420c.exe.exe
%Programs%\startup\95f04.exe.exe
%Programs%\startup\a2811.exe.exe
%Programs%\startup\b7920.exe.exe
%Programs%\startup\c79e5.exe.exe
%Programs%\startup\cd061.exe.exe
%Programs%\startup\ctfmon.exe
%Programs%\startup\dd374.exe.exe
%Programs%\startup\dde8d.exe.exe
%Programs%\startup\e5b1c.exe.exe
%Programs%\startup\e8d4b.exe.exe
%Programs%\startup\f52fb.exe.exe
%Programs%\startup\f8414.exe.exe
%Programs%\startup\fe2c4.exe.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).
  • %CommonDocuments% is a variable that refers to the file system directory that contains documents that are common to all users. A typical paths is C:\Documents and Settings\All Users\Documents.
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %CommonTemplates% is a variable that refers to the file system directory that contains the templates that are available to all users. A typical path is C:\Documents and Settings\All Users\Templates (Windows NT/2000/XP).
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %Favorites% is a variable that refers to the file system directory that serves as a common repository for the user's favorite items. A typical path is C:\Documents and Settings\[UserName]\Favorites.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %MyDocuments% is a variable that refers to the file system directory used to physically store a user's common repository of documents. A typical path is C:\Documents and Settings\[UserName]\My Documents.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.