Threat Search: 

ThreatExpert's Statistics for Virus.Win32.JunkPoly [Ikarus]:

Virus.Win32.JunkPoly [Ikarus] is also known as:
Threat AliasNumber of Incidents
Backdoor.ConstructKit [Symantec]45
BackDoor-DIQ [McAfee]45
not-a-virus:RemoteAdmin.Win32.PoisonIvy.j [Kaspersky Lab]45
Backdoor.ConstructKit!sd6 [PC Tools]33
Win-Trojan/Poison.2141184 [AhnLab]27
Backdoor:Win32/Poisonivy.E [Microsoft]24
Backdoor.Win32.PoisonIvy.az [Ikarus]21
Backdoor:Win32/Poison.M [Microsoft]15
Virus.Win32.Virut.ce [Kaspersky Lab]12
W32.Virut.CF [Symantec]12
Win32/Virut.F [AhnLab]12
W32/Virut.n.gen [McAfee]11
Mal/Scribble-C, W32/Scribble-B [Sophos]9
Virus:Win32/Virut.gen!O [Microsoft]9
Worm:Win32/Autorun.GX [Microsoft]7
Backdoor.Trojan [Symantec]6
not-a-virus:AdWare.Win32.FlyStudio.h [Kaspersky Lab]5
Mal/Generic-A [Sophos]4
Packed.Generic.181 [Symantec]4
Packed.Win32.Black.a [Kaspersky Lab]4
W32/Autorun.worm.gen [McAfee]4
Mal/Behav-285 [Sophos]3
New Malware.jn [McAfee]3
Suspicious.MH690 [Symantec]3
Trojan.DL.Agent.XGB [PC Tools]3
Virus:Win32/Virut.BM [Microsoft]3
W32/Scribble-B [Sophos]3
Infostealer.Gampass [Symantec]2
Mal/Basine-A, Mal/Behav-160, Mal/Emogen-E, Mal/Behav-009, Mal/Basine-C [Sophos]2
Mal/HckPk-A [Sophos]2
WORM_SDBOT.GAV [Trend Micro]2
Backdoor.Win32.FlyAgent.aa [Kaspersky Lab]1
Backdoor.Win32.FlyAgent.ju [Kaspersky Lab]1
Backdoor.Win32.FlyAgent.jx [Kaspersky Lab]1
Backdoor.Win32.FlyAgent.mc [Kaspersky Lab]1
BackDoor-CKB.dr [McAfee]1
Downloader [Symantec]1
Mal/Basine-A, Mal/Basine-C, Mal/Behav-160, Mal/Emogen-E, Mal/Behav-009 [Sophos]1
Mal/Basine-A, Mal/Behav-009, Mal/Basine-C [Sophos]1
Mal/Behav-010, Mal/Basine-A, Mal/Behav-191, Mal/Basine-C [Sophos]1
Mal/EncPk-GX, Mal/Basine-A, Mal/Basine-C, Mal/Behav-160, Mal/Emogen-E, Mal/Behav-009 [Sophos]1
Mal/PWS-Fam [Sophos]1
Malware.Virut [PC Tools]1
New Malware.bl [McAfee]1
New Malware.cc [McAfee]1
PWS-LDPinch!f [McAfee]1
PWS-OnlineGames.ed [McAfee]1
Trojan Horse [Symantec]1
TrojanDownloader:Win32/Small.gen!L [Microsoft]1
Trojan-GameThief.Win32.OnLineGames.uwhc [Kaspersky Lab]1
W32/AutoRun.worm.gen [McAfee]1
W32/Autorun.worm.h [McAfee]1
W32/Sdbot.worm [McAfee]1
Win-Trojan/Banker.904192.G [AhnLab]1
Win-Trojan/Black.736235 [AhnLab]1
Win-Trojan/LdPinch.2637 [AhnLab]1
Win-Trojan/OnlineGameHack.15648.AZ [AhnLab]1
Worm.Win32.AutoRun.qop [Kaspersky Lab]1
Worm.Win32.AutoRun.qpd [Kaspersky Lab]1
Worm.Win32.AutoRun.qqj [Kaspersky Lab]1
Worm.Win32.AutoRun.rui [Kaspersky Lab]1
Worm:Win32/Autorun.CK [Microsoft]1
WORM_AUTORUN.CSW [Trend Micro]1

Virus.Win32.JunkPoly [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China33
Brazil2
United Kingdom1

Virus.Win32.JunkPoly [Ikarus] is known to be created as:
%System%\306a39\00c3ac.exe
%System%\aionzz090329\aionzz.exe
%System%\dllcache\wuauclt.exe
%System%\wuauclt.exe
%Temp%\aionzz090329.exe
%Temp%\die.exe
%Temp%\nn.exe
%Temp%\server.exe
%Temp%\temp2.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).