Threat Search: 

ThreatExpert's Statistics for W32/Koobfa-Gen [Sophos]:

W32/Koobfa-Gen [Sophos] is also known as:
Threat AliasNumber of Incidents
W32.Koobface.A [Symantec]93
Worm.Win32.Koobface [Ikarus]60
Net-Worm.Win32.Koobface [Ikarus]52
Trojan-Proxy.Win32.Small [Ikarus]39
Downloader [Symantec]36
W32.Koobface.B [Symantec]34
Suspicious.MH690 [Symantec]32
Trojan Horse [Symantec]18
Net-Worm.Koobface [PC Tools]16
Generic.dx [McAfee]15
Net-Worm.Koobface!sd6 [PC Tools]12
Net-Worm.Win32.Koobface.ex [Kaspersky Lab]11
Backdoor.Win32.Lithium.h [Kaspersky Lab]8
Infostealer [Symantec]8
W32/Koobface.worm [McAfee]8
Net-Worm.Win32.Koobface.ez [Kaspersky Lab]7
Trojan.Win32.Agent [Ikarus]7
Trojan.Win32.Agent2.eqz [Kaspersky Lab]7
Trojan-Clicker.Win32.Small.adw [Kaspersky Lab]7
Trojan-Dropper.Agent [Ikarus]7
Backdoor.Win32.Lithium.dz [Kaspersky Lab]6
Net-Worm.Win32.Koobface.hn [Kaspersky Lab]6
Backdoor.Win32.Lithium.dy [Kaspersky Lab]5
Backdoor.Win32.Lithium.ed [Kaspersky Lab]5
Trojan.Win32.Inject.aaoh [Kaspersky Lab]5
Trojan-Spy.Win32.Agent.anap [Kaspersky Lab]5
WORM_KOOBFACE.E [Trend Micro]5
Net-Worm.Win32.Koobface.fp [Kaspersky Lab]4
Net-Worm.Win32.Koobface.k [Kaspersky Lab]4
Trojan.Win32.Agent2.hgm [Kaspersky Lab]4
Trojan-Spy.WinFlux [PC Tools]4
Win32/Koobface.worm.16384.M [AhnLab]4
Worm:Win32/Koobface.gen!D [Microsoft]4
Backdoor.Win32.Lithium.dx [Kaspersky Lab]3
Net-Worm.Win32.Koobface.d [Kaspersky Lab]3
Net-Worm.Win32.Koobface.jo [Kaspersky Lab]3
Trojan-Downloader.Agent!sd6 [PC Tools]3
Trojan-Downloader.Win32.Agent.atbf [Kaspersky Lab]3
Win32/Koobface.worm.27136 [AhnLab]3
Backdoor.Win32.Lithium.eh [Kaspersky Lab]2
Backdoor.Win32.Lithium.ei [Kaspersky Lab]2
Generic.dx!v [McAfee]2
Generic.dx!x [McAfee]2
Mal/Inet-Fam [Sophos]2
Net-Worm.Win32.Koobface.ck [Kaspersky Lab]2
Net-Worm.Win32.Koobface.ei [Kaspersky Lab]2
Net-Worm.Win32.Koobface.fj [Kaspersky Lab]2
Net-Worm.Win32.Koobface.he [Kaspersky Lab]2
Net-Worm.Win32.Koobface.hx [Kaspersky Lab]2
TROJ_DLOADR.AIT [Trend Micro]2
Trojan-Downloader [Ikarus]2
Trojan-Downloader.Win32.Agent.apmj [Kaspersky Lab]2
Trojan-Downloader.Win32.Alphabet [Ikarus]2
W32.Spybot.Worm [Symantec]2
W32/Koobfa-Gen, W32/Koobfa-Gen, Mal/KoobHeur-A [Sophos]2
Win32.Worm.Koobface [Ikarus]2
Win32/Koobface.worm.12288.V [AhnLab]2
Win32/Koobface.worm.13312 [AhnLab]2
Win-Trojan/Agent.14336.MO [AhnLab]2
Win-Trojan/Agent.73728.LD [AhnLab]2
Worm:Win32/Koobface.gen!A [Microsoft]2
Backdoor.Lithium!sd6 [PC Tools]1
Backdoor.Rbot [Ikarus]1
Backdoor.Win32.Agent.aekt [Kaspersky Lab]1
Backdoor.Win32.Agent.ubx [Kaspersky Lab]1
Backdoor.Win32.Lithium.dw [Kaspersky Lab]1
Downloader.Trojan [Symantec]1
Generic BackDoor [McAfee]1
Generic.dx!bdw [McAfee]1
Generic.dx!bp [McAfee]1
Generic.dx!cd [McAfee]1
Generic.dx!ce [McAfee]1
Generic.dx!ch [McAfee]1
Generic.dx!ci [McAfee]1
Generic.dx!cj [McAfee]1
Generic.dx!cv [McAfee]1
Generic.dx!df [McAfee]1
Generic.dx!ev [McAfee]1
Generic.dx!h [McAfee]1
Generic.dx!kq [McAfee]1
Generic.dx!n [McAfee]1
Generic.dx!rq [McAfee]1
Generic.dx!su [McAfee]1
Generic.dx!ve [McAfee]1
Generic.dx!w [McAfee]1
Net-Worm.Koobface.rv [PC Tools]1
Net-Worm.Win32.Koobface.a [Kaspersky Lab]1
Net-Worm.Win32.Koobface.aga [Kaspersky Lab]1
Net-Worm.Win32.Koobface.ago [Kaspersky Lab]1
Net-Worm.Win32.Koobface.ahx [Kaspersky Lab]1
Net-Worm.Win32.Koobface.ais [Kaspersky Lab]1
Net-Worm.Win32.Koobface.ap [Kaspersky Lab]1
Net-Worm.Win32.Koobface.aue [Kaspersky Lab]1
Net-Worm.Win32.Koobface.bm [Kaspersky Lab]1
Net-Worm.Win32.Koobface.bq [Kaspersky Lab]1
Net-Worm.Win32.Koobface.bt [Ikarus]1
Net-Worm.Win32.Koobface.bt [Kaspersky Lab]1
Net-Worm.Win32.Koobface.bu [Ikarus]1
Net-Worm.Win32.Koobface.bu [Kaspersky Lab]1
Net-Worm.Win32.Koobface.bz [Kaspersky Lab]1

W32/Koobfa-Gen [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation2
China1
Ukraine1

W32/Koobfa-Gen [Sophos] is known to be created as:
%ProgramFiles%\adult tube xxx codec\antivirus\dad.exe
%ProgramFiles%\adult tube xxx codec\antivirus\service.exe
%Temp%\freddy42.exe
%Temp%\kafan virlist 2009.03.31\090331-1-6.exe
%Temp%\net-worm.win32.koobface.k.exe
%Windir%\bolivar19.exe
%Windir%\bolivar20.exe
%Windir%\bolivar22.exe
%Windir%\bolivar23.exe
%Windir%\bolivar24.exe
%Windir%\bolivar25.exe
%Windir%\bolivar26.exe
%Windir%\bolivar27.exe
%Windir%\bolivar28.exe
%Windir%\bolivar29.exe
%Windir%\bolivar30.exe
%Windir%\bolivar31.exe
%Windir%\bolivar32.exe
%Windir%\bolivar33.exe
%Windir%\bolivar34.exe
%Windir%\che3.exe
%Windir%\che4.exe
%Windir%\fbtre6.exe
%Windir%\fbtre8.exe
%Windir%\freddy35.exe
%Windir%\freddy39.exe
%Windir%\freddy40.exe
%Windir%\freddy41.exe
%Windir%\freddy42.exe
%Windir%\freddy43.exe
%Windir%\freddy46.exe
%Windir%\freddy47.exe
%Windir%\freddy48.exe
%Windir%\freddy49.exe
%Windir%\fu01.exe
%Windir%\higeorge08.exe
%Windir%\higeorge09.exe
%Windir%\higeorge11.exe
%Windir%\julieta09.exe
%Windir%\ld01.exe
%Windir%\ld02.exe
%Windir%\ld03.exe
%Windir%\ld06.exe
%Windir%\ld07.exe
%Windir%\ld08.exe
%Windir%\ld09.exe
%Windir%\ld10.exe
%Windir%\ld11.exe
%Windir%\ld12.exe
%Windir%\mstre.exe
%Windir%\mstre10.exe
%Windir%\mstre12.exe
%Windir%\mstre15.exe
%Windir%\mstre16.exe
%Windir%\mstre18.exe
%Windir%\mstre19.exe
%Windir%\muchomambo01.exe
%Windir%\nl07.exe
%Windir%\nl12.exe
%Windir%\pp02.exe
%Windir%\pp06.exe
%Windir%\pp09.exe
%Windir%\pp1.exe
%Windir%\pp10.exe
%Windir%\pp2.exe
%Windir%\romeo13.exe
%Windir%\romeo15.exe
%Windir%\tag09.exe
%Windir%\tag10.exe
%Windir%\tag12.exe
%Windir%\twitty01.exe
%Windir%\ugo01.exe
%Windir%\ugo02.exe
%Windir%\yb07.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.