Threat Search: 

ThreatExpert's Statistics for VirTool:Win32/Injector.gen!AH [Microsoft]:

VirTool:Win32/Injector.gen!AH [Microsoft] is also known as:
Threat AliasNumber of Incidents
BackDoor-CEP.gen.am [McAfee]17
Mal/Generic-A [Sophos]16
Backdoor.Trojan [Symantec]14
Trojan-Dropper.Win32.Hupigon [Ikarus]13
Troj/Bifrose-YH [Sophos]11
Backdoor.Win32.Bifrose.fqv [Kaspersky Lab]10
VirTool:Win32/CeeInject.gen!J [Microsoft]10
Infostealer [Symantec]7
Trojan.Win32.Midgare.ppr [Kaspersky Lab]7
Generic.dx [McAfee]6
Backdoor.Win32.Bifrose.fqs [Kaspersky Lab]5
Trojan Horse [Symantec]5
VirTool.Win32.Injector [Ikarus]5
Generic Dropper.dq [McAfee]4
Mal/Behav-103, Mal/Behav-043 [Sophos]4
Trojan.Midgare!sd6 [PC Tools]4
Trojan.Win32.Midgare.adjf [Kaspersky Lab]4
Trojan-Dropper.Agent [Ikarus]4
Mal/Generic-E [Sophos]3
Trojan.Midgare [Ikarus]3
VirTool:Win32/Injector.gen!AG [Microsoft]3
W32.Ackantta.B@mm [Symantec]3
W32/Autorun-AQL [Sophos]3
Win-Trojan/Midgare.39325 [AhnLab]3
Infostealer.Banker.C [Symantec]2
Trojan.Win32.Midgare.qnl [Kaspersky Lab]2
W32/AutoVrt-Gen, Mal/CryptBox-A [Sophos]2
Win-Trojan/Buzus.70656.J [AhnLab]2
Win-Trojan/Midgare.69091 [AhnLab]2
Backdoor.Sdbot [Symantec]1
Backdoor.Win32.Bifrose.aeqy [Kaspersky Lab]1
Backdoor.Win32.SdBot [Ikarus]1
Backdoor.Win32.SdBot.obo [Kaspersky Lab]1
Generic BackDoor.u [McAfee]1
Generic.dx!ewu [McAfee]1
Generic.dx!exz [McAfee]1
Generic.dx!eyn [McAfee]1
Mal/EncPk-IT, Mal/EncPk-FL, Mal/MDrop-Gen [Sophos]1
Packed.Win32.Tdss [Ikarus]1
Packed.Win32.Tdss.c [Kaspersky Lab]1
Trojan.Win32.Buzus [Ikarus]1
Trojan.Win32.Buzus.anee [Kaspersky Lab]1
Trojan.Win32.Buzus.bxlo [Kaspersky Lab]1
Trojan.Win32.Buzus.bxlr [Kaspersky Lab]1
Trojan.Win32.Buzus.bxma [Kaspersky Lab]1
Trojan.Win32.Midgare.adir [Kaspersky Lab]1
Trojan-Dropper.Poison.B [Ikarus]1
Virus.Win32.Bifrose [Ikarus]1
W32/Palack.worm [McAfee]1
W32/Sdbot.worm!dz [McAfee]1
Win32/Ackantta.worm.266240 [AhnLab]1
Win32/Ackantta.worm.52224 [AhnLab]1
Win32/IRCBot.worm.variant [AhnLab]1
Win-Trojan/Midgare.65365 [AhnLab]1
Win-Trojan/Spambot.251904 [AhnLab]1

VirTool:Win32/Injector.gen!AH [Microsoft] is known to be created as:
%AppData%\bifrost\server.exe
%AppData%\messanger\msn.exe
%AppData%\windows update\winupdate.exe
%ProgramFiles%\123s.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\tata.exe
%ProgramFiles%\doda\setup.exe
%ProgramFiles%\saw.exe
%ProgramFiles%\windowsdll\windowsdll.exe
%ProgramFiles%\windowsupdate\temp.exe
%System%\1.exe
%System%\bifrost\lol.exe
%System%\bifrost\server.exe
%System%\bifrost\syti.exe
%System%\explorer\win32.exe
%System%\javaa.exe
%System%\javale.exe
%System%\javame1.1.exe
%System%\jushred.exe
%System%\massenger live\server.exe
%System%\messanger\msn.exe
%System%\msn\server.exe
%System%\qq\a.exe
%System%\sdra64.exe
%System%\skype\skype.scr
%System%\spool1\spool.exe
%System%\system32.exe
%System%\system32\logon.scr
%System%\windowesdll\windowesdll.exe
%System%\windows update\winupdate.exe
%System%\windows\msn.exe
%Temp%\dos-sql-php.99.exe
%Temp%\ixp000.tmp\dunhill.exe
%Temp%\ixp000.tmp\dzgmax.exe
%Temp%\ixp000.tmp\sms-.exe
%Temp%\server.exe
%Windir%\1.exe
%Windir%\a.exe
%Windir%\noom\server.exe
%Windir%\system\a1.exe
%Windir%\system44\system44.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.