Threat Search: 

ThreatExpert's Statistics for VirTool:Win32/VBInject.gen!BP [Microsoft]:

VirTool:Win32/VBInject.gen!BP [Microsoft] is also known as:
Threat AliasNumber of Incidents
Trojan Horse [Symantec]26
VirTool.Win32.VBInject [Ikarus]22
Backdoor.Trojan [Symantec]21
Mal/Generic-A [Sophos]19
Trojan.Generic [PC Tools]19
Generic Dropper.lj [McAfee]16
Trojan.Win32.VB.zbt [Kaspersky Lab]15
Backdoor.Trojan [PC Tools]14
Troj/Zbot-GC [Sophos]14
W32.Spybot.Worm [Symantec]10
Backdoor.Win32.Poison.aqqf [Kaspersky Lab]9
HackTool.Win32.Crypt [Ikarus]8
Generic VB.i [McAfee]7
Backdoor.Win32.Poison.baov [Kaspersky Lab]6
Troj/VBInject-E [Sophos]6
Generic BackDoor.b [McAfee]5
Mal/Behav-221 [Sophos]5
Trojan.Win32.Zbot [Ikarus]5
Trojan-PSW.Win32.Dybalom.bg [Kaspersky Lab]5
Backdoor.Win32.Bifrose.cfxa [Kaspersky Lab]4
BackDoor-DZP [McAfee]4
Trojan.Win32.Buzus [Ikarus]4
Win-Trojan/Xema.variant [AhnLab]4
BackDoor-DWZ [McAfee]3
Trojan.Win32.Buzus.caen [Kaspersky Lab]3
Trojan.Win32.VB.uzs [Kaspersky Lab]3
Win-Trojan/Poison.85432 [AhnLab]3
Backdoor.Win32.Poison [Ikarus]2
Mal/Generic-E [Sophos]2
Mal/VBDrop-G, Mal/VBInject-G, Mal/VBInject-G [Sophos]2
Packed.Win32.Krap.ai [Kaspersky Lab]2
Trojan.Win32.Buzus.bsrt [Kaspersky Lab]2
Trojan.Win32.Buzus.cckd [Kaspersky Lab]2
Trojan.Win32.Midgare.ahuf [Kaspersky Lab]2
Trojan.Win32.Pincav.lem [Kaspersky Lab]2
Trojan.Win32.Pincav.oqd [Kaspersky Lab]2
Trojan.Win32.Pincav.pox [Kaspersky Lab]2
Trojan.Win32.Pincav.prc [Kaspersky Lab]2
Trojan.Win32.Scar.atws [Kaspersky Lab]2
Trojan.Win32.VBKrypt.bm [Kaspersky Lab]2
Trojan-Downloader.Win32.VB.qcw [Kaspersky Lab]2
Win-Trojan/Agent2.60950 [AhnLab]2
Backdoor.Win32.Bifrose.bhrs [Kaspersky Lab]1
Backdoor.Win32.Bredolab.beg [Kaspersky Lab]1
Backdoor.Win32.Bredolab.bhq [Kaspersky Lab]1
Backdoor.Win32.Bredolab.clr [Kaspersky Lab]1
Backdoor.Win32.Poison.acws [Kaspersky Lab]1
Backdoor.Win32.Poison.amer [Kaspersky Lab]1
Backdoor.Win32.Poison.amxv [Kaspersky Lab]1
Backdoor.Win32.Poison.anzb [Kaspersky Lab]1
Backdoor.Win32.Poison.anzo [Kaspersky Lab]1
Backdoor.Win32.Poison.asff [Kaspersky Lab]1
Backdoor.Win32.Poison.awrg [Kaspersky Lab]1
Backdoor.Win32.Poison.yni [Kaspersky Lab]1
BackDoor-CEP!ic [McAfee]1
Backdoor-CEP.gen.a [McAfee]1
Dropper/Bvb.713728 [AhnLab]1
Dropper/Xema.8556905 [AhnLab]1
Generic BackDoor!bjf [McAfee]1
Generic BackDoor.ah [McAfee]1
Generic Downloader.x!bii [McAfee]1
Generic Dropper.ka [McAfee]1
Generic.dx!glk [McAfee]1
Generic.dx!hhi [McAfee]1
Generic.dx!ier [McAfee]1
Generic.dx!itc [McAfee]1
Generic.dx!kji [McAfee]1
Mal/VBDrop-G [Sophos]1
Packed.Win32.PePatch.jw [Kaspersky Lab]1
Packed.Win32.PolyCrypt [Ikarus]1
Packed.Win32.PolyCrypt.b [Kaspersky Lab]1
Scar.gen [McAfee]1
Spam-Mailbot [McAfee]1
Suspicious.MH690 [Symantec]1
Troj/VB-EIG [Sophos]1
Trojan.Buzus [PC Tools]1
Trojan.Win32.Buzus.btaq [Kaspersky Lab]1
Trojan.Win32.Buzus.btjt [Kaspersky Lab]1
Trojan.Win32.Buzus.ckeo [Kaspersky Lab]1
Trojan.Win32.Genome [Ikarus]1
Trojan.Win32.Genome.cjeg [Kaspersky Lab]1
Trojan.Win32.Midgare.ahuk [Kaspersky Lab]1
Trojan.Win32.Refroso [Ikarus]1
Trojan.Win32.Refroso.nqx [Kaspersky Lab]1
Trojan.Win32.Refroso.tvx [Kaspersky Lab]1
Trojan.Win32.Scar [Ikarus]1
Trojan.Win32.VB [Ikarus]1
Trojan.Win32.VB.vhn [Kaspersky Lab]1
Trojan.Win32.VB.vkb [Kaspersky Lab]1
Trojan.Win32.Zmunik.aq [Kaspersky Lab]1
Trojan-Downloader.Win32.VB [Ikarus]1
Trojan-Dropper [Ikarus]1
Trojan-Dropper.Win32.VB [Ikarus]1
Trojan-Dropper.Win32.VB.acyc [Kaspersky Lab]1
Trojan-Dropper.Win32.VB.addr [Kaspersky Lab]1
Trojan-PWS.Win32.Dybalom [Ikarus]1
VirTool.Win32.Vbcrypt [Ikarus]1
VirTool.Win32.Vbinder [Ikarus]1
Win-Trojan/Bifrose.66178 [AhnLab]1
Win-Trojan/Buzus.61586 [AhnLab]1

VirTool:Win32/VBInject.gen!BP [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Germany42
Spain28
Brazil3
Kyrgyzstan1
Portugal1
Taiwan1

VirTool:Win32/VBInject.gen!BP [Microsoft] is known to be created as:
%AppData%\bifrost\server.exe
%AppData%\server.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\winzip\winzip.exe
%System%\avg.exe
%System%\bifrost\server.exe
%System%\cerberus\server.exe
%System%\crypted.exe
%System%\csmi\csmi.exe
%System%\msn\eid.exe
%System%\msn\msn.exe
%System%\nod143.exe
%System%\sdra64.exe
%System%\servises.exe
%System%\system32\windows.exe
%System%\systeme\wingard.exe
%System%\taskmrg.exe
%System%\windows update\winupdate.exe
%System%\wuamgrd.exe
%System%\wupdate.exe
%System%\zoro\mrm.exe
%System%\zzt\rh.exe
%Temp%\cryptedfile.exe
%Temp%\ixp000.tmp\crypted.exe
%Temp%\ixp000.tmp\msn.exe
%Temp%\ixp000.tmp\p2p.exe
%Temp%\ixp000.tmp\reptile.exe
%Temp%\sa-hacker.exe
%Temp%\server.exe
%Temp%\skype_new.exe
%Windir%\1.exe
%Windir%\bekstak.exe.exe
%Windir%\bifrost\server.exe
%Windir%\microsoftupdat\update.exe
%Windir%\mstwain32.exe
%Windir%\scenecrypt\scenecrypt.exe
%Windir%\scssrr.exe
%Windir%\server.exe
%Windir%\spoolsv.exe
%Windir%\svchost.exe.exe
%Windir%\winampa.exe
%Windir%\winlogonn.exe
%Windir%\winudpmgr.exe
c:\avg.exe
c:\extracted\22.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.