Threat Search: 

ThreatExpert's Statistics for VirTool.Win32.Vbinder [Ikarus]:

VirTool.Win32.Vbinder [Ikarus] is also known as:
Threat AliasNumber of Incidents
VirTool:Win32/Vbinder.V [Microsoft]42
Backdoor.Trojan [Symantec]26
Mal/Generic-A [Sophos]22
VirTool:Win32/Vbinder.P [Microsoft]21
VirTool:Win32/Vbinder.gen!G [Microsoft]19
Mal/Dropper-AL [Sophos]12
Trojan Horse [Symantec]12
Backdoor.Poison!sd6 [PC Tools]11
Win-Trojan/LdPinch.131072.E [AhnLab]11
Win-Trojan/Xema.variant [AhnLab]10
Backdoor.Win32.Poison.sab [Kaspersky Lab]9
Backdoor-DZP [McAfee]9
Win-Trojan/Poison.90185 [AhnLab]9
Generic VB.z [McAfee]7
VirTool:Win32/Vbinder.gen!GL [Microsoft]7
VirTool:Win32/VBInject.gen!AN [Microsoft]7
VirTool:Win32/VBInject.gen!CN [Microsoft]7
Backdoor.Bifrose [Symantec]6
Backdoor.Sdbot [Symantec]6
Trojan.Win32.VB.uyk [Kaspersky Lab]6
Trojan-Spy.Win32.Zbot.acwk [Kaspersky Lab]6
Backdoor.Win32.Bifrose.areq [Kaspersky Lab]5
Backdoor.Win32.SdBot.nbb [Kaspersky Lab]5
Generic.dx [McAfee]5
VirTool:Win32/VBInject.CR [Microsoft]5
Backdoor.Win32.Bifrose.aqnw [Kaspersky Lab]4
Backdoor.Win32.Poison.tjz [Kaspersky Lab]4
BackDoor-CEP.gen.aq [McAfee]4
Generic BackDoor [McAfee]4
Troj/Vbinder-B [Sophos]4
Trojan.Win32.VB.abhw [Kaspersky Lab]4
VirTool:Win32/Vbinder.M [Microsoft]4
Win-Trojan/Poison.90112.B [AhnLab]4
Backdoor-CEP.gen.c [McAfee]3
Generic Dropper [McAfee]3
Generic VB.ay [McAfee]3
Generic VB.i [McAfee]3
Mal/Dropper-AO [Sophos]3
Trojan.Win32.Refroso.awi [Kaspersky Lab]3
VirTool:Win32/Obfuscator.DM [Microsoft]3
VirTool:Win32/Vbinder.AC [Microsoft]3
VirTool:Win32/Vbinder.Q [Microsoft]3
VirTool:Win32/VBInject.gen!BW [Microsoft]3
W32.IRCBot [Symantec]3
Win-Trojan/Bifrose.4685824 [AhnLab]3
Win-Trojan/Bifrose.61440.K [AhnLab]3
Win-Trojan/Buzus.32768.AC [AhnLab]3
Backdoor.Win32.Bifrose.akqv [Kaspersky Lab]2
Backdoor.Win32.Bifrose.aqpz [Kaspersky Lab]2
Backdoor.Win32.Bifrose.bphi [Kaspersky Lab]2
Backdoor.Win32.IRCBot.mbn [Kaspersky Lab]2
Backdoor.Win32.Poison.ajrq [Kaspersky Lab]2
Backdoor.Win32.Poison.qns [Kaspersky Lab]2
Backdoor.Win32.Poison.toj [Kaspersky Lab]2
Backdoor.Win32.Poison.tyc [Kaspersky Lab]2
Backdoor.Win32.Poison.vqs [Kaspersky Lab]2
Backdoor.Win32.Poison.wan [Kaspersky Lab]2
Backdoor.Win32.SdBot.nin [Kaspersky Lab]2
Backdoor-CEP [McAfee]2
Generic VB.c [McAfee]2
Generic VB.h [McAfee]2
MultiDropper-SO [McAfee]2
Packed.Generic.266 [Symantec]2
Trojan.Win32.VB.gpi [Kaspersky Lab]2
Trojan.Win32.VB.hok [Kaspersky Lab]2
Trojan.Win32.VB.iee [Kaspersky Lab]2
Trojan-Dropper.Win32.Typic.aiq [Kaspersky Lab]2
Trojan-Dropper.Win32.VB.icm [Kaspersky Lab]2
VirTool:Win32/Acillatem [Microsoft]2
VirTool:Win32/Vbinder.H [Microsoft]2
Virus:Win32/Sality.AM [Microsoft]2
W32.Ackantta.B@mm [Symantec]2
W32.Sality.AE [Symantec]2
W32/Sality.gen [McAfee]2
W32/Sality-AM [Sophos]2
W32/Sdbot.worm.gen.cm [McAfee]2
Win32/IRCBot.worm.variant [AhnLab]2
Win32/Kashu.B [AhnLab]2
Win-Trojan/Bifrose.77824.Q [AhnLab]2
Win-Trojan/Poison.167936 [AhnLab]2
Win-Trojan/Poison.20480.DH [AhnLab]2
Worm:Win32/Hamweq.AD [Microsoft]2
Backdoor.Bifrose!sd6 [PC Tools]1
Backdoor.Bifrose.akqv [PC Tools]1
Backdoor.Win32.Bifrose.anwr [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqma [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqmf [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqqg [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqrk [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqsm [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqsn [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aqws [Kaspersky Lab]1
Backdoor.Win32.Bifrose.arxz [Kaspersky Lab]1
Backdoor.Win32.Bifrose.fod [Kaspersky Lab]1
Backdoor.Win32.Bifrose.foo [Kaspersky Lab]1
Backdoor.Win32.Nytroloh.kr [Kaspersky Lab]1
Backdoor.Win32.Poison.accz [Kaspersky Lab]1
Backdoor.Win32.Poison.aixn [Kaspersky Lab]1
Backdoor.Win32.Poison.akzg [Kaspersky Lab]1
Backdoor.Win32.Poison.badx [Kaspersky Lab]1

VirTool.Win32.Vbinder [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Germany10
Spain10
Russian Federation9
Sweden2
United Kingdom2
France1
Saudi Arabia1

VirTool.Win32.Vbinder [Ikarus] is known to be created as:
%AppData%\systemproc\lsass.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\microsoft\svchost.exe
%ProgramFiles%\real\real.exe
%System%\antivirus1.exe
%System%\autoupdate.exe
%System%\bifrost\server.exe
%System%\cde32.exe
%System%\foto1.exe
%System%\fservice.exe
%System%\googlebuzzer.exe
%System%\googleupservice.exe
%System%\igsftors32.exe
%System%\lkjh\explorer.exe
%System%\msupdt.exe
%System%\netlibrary.exe
%System%\scvhost.exe
%System%\sdra64.exe
%System%\smss32.exe
%System%\ststem33\system32s.exe
%System%\sys.exe
%System%\vhost\server.exe
%System%\win32ini\svchost.exe
%System%\windoos.exe
%System%\windoos\0.exe
%System%\windows.exe
%System%\winlogon32.exe
%System%\wins.exe
%System%\wjkfrfiq.exe
%System%\wupdate.exe
%Temp%\asdasdad.exe
%Temp%\ixp000.tmp\1.exe
%Temp%\ixp000.tmp\benita.exe
%Temp%\ixp000.tmp\f.exe
%Temp%\ixp000.tmp\f0t0.exe
%Temp%\ixp000.tmp\indetecable.exe
%Temp%\ixp000.tmp\lol.exe
%Temp%\ixp000.tmp\msn.exe
%Temp%\ixp000.tmp\setup.exe
%Temp%\ixp001.tmp\indetecable2.exe
%Temp%\mmm.exe
%Temp%\msnmsgr.exe
%Temp%\ohyes.exe
%Temp%\poi.exe
%Temp%\s.exe
%Temp%\svchost1.exe
%Windir%\fxstaller.exe
%Windir%\iexplore.exe
%Windir%\installed.exe
%Windir%\madbbcre.exe
%Windir%\mkdir\dll.exe
%Windir%\services.exe
%Windir%\svchost.exe.exe
%Windir%\system\sservice.exe
%Windir%\system\svchost.exe
%Windir%\system32:setub.exe
%Windir%\system32:svchost.exe
%Windir%\temp\wpv141259018327.exe
%Windir%\temp\wpv491259018327.exe
%Windir%\winnt.exe
%Windir%\winudpmgr.exe
%Windir%\wkssevr.exe
%Windir%\xplorer.exe
c:\fotoshop.exe
c:\system\g-923-321232-3232-32211-23\driver.exe
c:\windows.exe
c:\windows:dam.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.