Threat Search: 

ThreatExpert's Statistics for Virus.Win32.Agent.COH [Ikarus]:

Virus.Win32.Agent.COH [Ikarus] is also known as:
Threat AliasNumber of Incidents
Win-Trojan/Xema.variant [AhnLab]53
BackDoor-DRV.gen.c [McAfee]27
Mal/Generic-A [Sophos]23
Worm:Win32/Autorun.JC [Microsoft]13
not-a-virus:FraudTool.Win32.GameBot.b [Kaspersky Lab]9
Generic.dx [McAfee]5
Adware.PigSearch [Symantec]4
Mal/UnkPack-Fam [Sophos]4
Trojan:Win32/Meredrop [Microsoft]4
W32/Autorun.worm.gen [McAfee]4
Trojan-Dropper.Win32.Agent.agum [Kaspersky Lab]2
Worm.Win32.AutoRun.wbu [Kaspersky Lab]2
Worm:Win32/Autorun.MBS [Microsoft]2
Backdoor.Win32.Hupigon.gqcr [Kaspersky Lab]1
Infostealer.Gampass [Symantec]1
Mal/Behav-043 [Sophos]1
Mal/Packer [Sophos]1
Troj/Jusabli-A [Sophos]1
Trojan Horse [Symantec]1
Trojan.Downexec.D!inf [Symantec]1
Trojan.PWS.QQPass [Symantec]1
Trojan.Win32.Agent.chgh [Kaspersky Lab]1
Trojan.Win32.Agent2.edf [Kaspersky Lab]1
Trojan.Win32.KillFiles.ayb [Kaspersky Lab]1
Trojan.WinREG.StartPage.t [Kaspersky Lab]1
Trojan:Win32/Cosisrop!rts [Microsoft]1
Trojan-Downloader.Win32.FlyStudio.bg [Kaspersky Lab]1
Trojan-Dropper.Win32.Flystud.rm [Kaspersky Lab]1
Trojan-Dropper.Win32.StartPage.a [Kaspersky Lab]1
TrojanDropper:Win32/Dunik!rts [Microsoft]1
Trojan-GameThief.Win32.OnLineGames.spio [Kaspersky Lab]1
Trojan-PSW.Win32.Flystudio.g [Kaspersky Lab]1
Trojan-PSW.Win32.LdPinch.afvp [Kaspersky Lab]1
Virus.Win32.Downloader.bi [Kaspersky Lab]1
Virus:Win32/Jusabli.A [Microsoft]1
W32.SillyFDC [Symantec]1
W32/Kernout-A [Sophos]1
Win32/Mahao [AhnLab]1
Worm.AutoRun.GEN [PC Tools]1

Virus.Win32.Agent.COH [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China88
Italy4
France1
Taiwan1

Virus.Win32.Agent.COH [Ikarus] is known to be created as:
%FontsDir%\binail.exe
%ProgramFiles%\daemon tools lite\ctfnom.exe
%System%\bbplay\bb.exe
%System%\bbplayer.exe
%System%\ercservdin.exe
%System%\goolgepy.exe
%System%\qqpet\qqpet\qqpetagent.exe
%System%\winrsv.exe
%Temp%\090523-a-9.exe
%Temp%\kafan virlist 2009.03.05\090305-1-6.exe
%Temp%\kafan virlist 2009.04.07\090407-3-7.exe
%Temp%\kb.exe
%Temp%\tddownload\1.exe
%Temp%\wd.exe
%Windir%\cm3.exe
%Windir%\svch0s.exe
Notes:
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.