Threat Search: 

ThreatExpert's Statistics for W32.Gammima [Symantec]:

W32.Gammima [Symantec] is also known as:
Threat AliasNumber of Incidents
Trojan.Lineage.Gen!Pac.3 [PC Tools]138
PWS-Gamania.gen.a [McAfee]127
Mal/EncPk-CE [Sophos]75
Generic PWS.ak [McAfee]60
Worm:Win32/Taterf.B [Microsoft]58
PWS:Win32/Frethog.gen!B [Microsoft]40
Mal_NSAnti-1 [Trend Micro]38
Packed.Win32.Krap.b [Kaspersky Lab]37
Trojan.Win32.Inhoo [Ikarus]37
PWS-LegMir.gen.k.dll [McAfee]32
New Malware.hz [McAfee]26
Troj/Virtum-Gen [Sophos]25
Packed.Win32.Krap [Ikarus]24
Malware.Gammima [PC Tools]23
Trojan-GameThief.Win32.Magania [Ikarus]23
WORM_AUTORUN.UL [Trend Micro]21
Worm:Win32/Taterf.A.dll [Microsoft]20
Generic.dx [McAfee]19
PWS:Win32/Frethog.D [Microsoft]18
Trojan:Win32/Inhoo.A [Microsoft]18
Worm:Win32/Taterf.B.dll [Microsoft]17
Generic PWS.y [McAfee]16
Win-Trojan/MalPacked.Gen [AhnLab]16
Worm.Win32.AutoRun [Ikarus]16
Mal/Generic-A [Sophos]15
Trojan-GameThief.Win32.OnLineGames.yze [Kaspersky Lab]15
Mal/Delf-M [Sophos]14
Mal/EncPk-JS [Sophos]14
Mal/Generic-A, Troj/Virtum-Gen [Sophos]14
TrojanDownloader:Win32/Frethog.C [Microsoft]14
TrojanSpy:Win32/Hitpop.AG [Microsoft]13
PWS-Mmorpg.gen [McAfee]12
Trojan-GameThief.Win32.OnLineGames [Ikarus]12
Trojan.Lineage.Gen!Pac.7 [PC Tools]11
Packed.Win32.Krap.g [Kaspersky Lab]10
Trojan-PSW.Win32.OnLineGames.syv [Kaspersky Lab]10
Worm.Win32.AutoRun.cea [Kaspersky Lab]10
WORM_ONLINEG.DSO [Trend Micro]10
Mal/Frethog-B [Sophos]9
Mal/LineDLL-B, Mal/Packer [Sophos]9
PWS-LegMir.dll [McAfee]9
Trojan.Crypt [Ikarus]9
Trojan.Onlinegames.Gen!Pac.73 [PC Tools]9
TrojanDownloader:Win32/Injector.gen!W [Microsoft]9
Trojan-GameThief.Win32.OnLineGames.vrdp [Kaspersky Lab]9
Worm:Win32/Taterf.gen!C [Microsoft]9
Packed.Win32.NSAnti.r [Kaspersky Lab]8
VirTool:WinNT/Vanti.gen!C [Microsoft]8
W32/Autorun-ABV [Sophos]8
PWS-Gamania.gen.n [McAfee]7
Trojan-PWS.OnlineGames.ARun [PC Tools]7
Trojan-Spy.Win32.Pophot.bod [Kaspersky Lab]7
Win-Trojan/Xema.variant [AhnLab]7
Bloodhound.Unknown [Symantec]6
Mal/EncPk-DH [Sophos]6
Mal/EncPk-EK [Sophos]6
PWS:Win32/OnLineGames.AH [Microsoft]6
PWS-Gamania.gen.g [McAfee]6
Trojan.PWS.OnLineGames.BER [PC Tools]6
TrojanDownloader:Win32/Small.gen!AA [Microsoft]6
Trojan-GameThief.Win32.Magania.aufj [Kaspersky Lab]6
Trojan-Spy.Gampass [PC Tools]6
TSPY_LEGMIR.APG [Trend Micro]6
TSPY_MAGANIA.TM [Trend Micro]6
Win-Trojan/Magania.87040.AQ [AhnLab]6
Worm.Win32.Taterf [Ikarus]6
Mal/EncPk-CE, Mal/EncPk-DH [Sophos]5
Mal/EncPk-IG [Sophos]5
Mal/EncPk-IG, Mal/EncPk-HI [Sophos]5
Mal/Packer [Sophos]5
PWS:Win32/Frethog.gen!L [Microsoft]5
PWS-LegMir.gen.k [McAfee]5
Troj/PWSDle-Gen [Sophos]5
TrojanDownloader:Win32/Zlob.BBD [Microsoft]5
Trojan-PSW.Win32.OnLineGames.yze [Kaspersky Lab]5
W32/Autorun.worm.bx.gen.dll [McAfee]5
Dropper/Agent.70959 [AhnLab]4
Mal/UnkPack-Fam [Sophos]4
Packer.Malware.NSAnti.BH [Ikarus]4
PWS:Win32/Frethog.AJ [Microsoft]4
PWS-Mmorpg!fv [McAfee]4
PWS-OnlineGames.bl [McAfee]4
TROJ_VANTI.VV [Trend Micro]4
Trojan.Win32.Vaklik [Ikarus]4
Trojan-Downloader.Win32.Frethog [Ikarus]4
Trojan-Dropper.Win32.Agent.azfz [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.aikz [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.aizk [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.akqd [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.audm [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.bgsu [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.bvqu [Kaspersky Lab]4
Trojan-GameThief.Win32.Magania.ccdt [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.safa [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.sfwl [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.sisd [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.sjtb [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.sqid [Kaspersky Lab]4
Trojan-GameThief.Win32.OnLineGames.vrbp [Kaspersky Lab]4
Trojan-PSW.OnLineGames!sd5 [PC Tools]4

W32.Gammima [Symantec] has the following possible country of origin:
OriginNumber of Incidents
China50

W32.Gammima [Symantec] is known to be created as:
%System%\ahnfgss0.dll
%System%\ahnfgss1.dll
%System%\ahnfgss2.dll
%System%\ahnsbsb.exe
%System%\ahnxsds0.dll
%System%\amvo.exe
%System%\amvo0.dll
%System%\amvo1.dll
%System%\amvo2.dll
%System%\avpo.exe
%System%\avpo0.dll
%System%\avpo1.dll
%System%\ckvo.exe
%System%\ckvo0.dll
%System%\ckvo1.dll
%System%\ckvo2.dll
%System%\dse235rgd0.dll
%System%\fool0.dll
%System%\fool2.dll
%System%\gasretyw0.dll
%System%\gasretyw2.dll
%System%\ierdfgh.exe
%System%\ieso0.dll
%System%\ieso1.dll
%System%\j3ewro.exe
%System%\jvvo.exe
%System%\jvvo0.dll
%System%\jvvo1.dll
%System%\kamsoft.exe
%System%\kavo.exe
%System%\kavo0.dll
%System%\kavo1.dll
%System%\kavo2.dll
%System%\kva8wr.exe
%System%\kxvo.exe
%System%\kxvo0.dll
%System%\kxvo1.dll
%System%\lhgjyit0.dll
%System%\lhgjyit1.dll
%System%\lhgjyit2.dll
%System%\mmvo.exe
%System%\mmvo0.dll
%System%\mmvo1.dll
%System%\nmdfgds0.dll
%System%\nmdfgds1.dll
%System%\nmdfgds2.dll
%System%\olhrwef.exe
%System%\pytdfse0.dll
%System%\pytdfse1.dll
%System%\revo0.dll
%System%\revo1.dll
%System%\syssfge.exe
%System%\tavo.exe
%System%\tavo0.dll
%System%\tavo1.dll
%System%\uret463.exe
%System%\uweyiwe0.dll
%System%\uweyiwe1.dll
%System%\uweyiwe2.dll
%System%\wedasgads0.dll
%System%\wedasgads2.dll
%Temp%\0cd0a401.exe
%Temp%\3.exe
%Temp%\4tddfwq0.dll
%Temp%\4tddfwq1.dll
%Temp%\54mo4e.dll
%Temp%\7hr.dll
%Temp%\8.dll
%Temp%\843wee1.dll
%Temp%\a81lkgv.com
%Temp%\avp.exe
%Temp%\cvasds0.dll
%Temp%\cvasds1.dll
%Temp%\cvasds2.dll
%Temp%\ekgwob.dll
%Temp%\fgyxgap2.dll
%Temp%\fool0.dll
%Temp%\fool1.dll
%Temp%\gz8lf.dll
%Temp%\herss.exe
%Temp%\ieso0.dll
%Temp%\ieso1.dll
%Temp%\ixp000.tmp\down.exe
%Temp%\ktly\ktly.exe
%Temp%\kxvo.exe
%Temp%\l.dll
%Temp%\lhgjyit0.dll
%Temp%\lhgjyit1.dll
%Temp%\lhgjyit2.dll
%Temp%\luk1ylq.com
%Temp%\ntde1ect.com
%Temp%\sl.dll
%Temp%\systemt.dll
%Temp%\uret463.exe
%Temp%\xlk9.com
%Temp%\xvassdf.exe
%Temp%\zsmd5li.dll
%Windir%\2.exe
%Windir%\help\db4cafbc4c43.exe
%Windir%\help\f3c74e3fa248.dll
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.