Threat Search: 

ThreatExpert's Statistics for Win32.Outbreak [Ikarus]:

Win32.Outbreak [Ikarus] is also known as:
Threat AliasNumber of Incidents
Spy-Agent.bw [McAfee]17
TrojanDropper:Win32/Emold.C [Microsoft]15
Trojan Horse [Symantec]11
Infostealer [Symantec]10
Mal/EncPk-CZ [Sophos]10
W32.SillyFDC [Symantec]10
TrojanSpy:Win32/Zbot.gen!C [Microsoft]7
W32.Auraax [Symantec]7
PWS:Win32/Zbot.VA [Microsoft]6
Worm.AutoRun!sd6 [PC Tools]6
Generic Dropper [McAfee]5
Infostealer.Banker.C [Symantec]5
Mal/EncPk-GL [Sophos]5
Emold.gen [McAfee]4
Mal/EncPk-GH [Sophos]4
Generic Downloader.x [McAfee]3
W32/Autorun.worm.gen [McAfee]3
Worm.Autorun.LUY [PC Tools]3
Backdoor.Trojan [Symantec]2
Downloader [Symantec]2
Packed.Win32.Krap.x [Kaspersky Lab]2
PWS-Zbot [McAfee]2
Spy-Agent.bv.dldr [McAfee]2
Troj/Agent-HVD [Sophos]2
Troj/Agent-HYP [Sophos]2
Troj/Agent-ICK [Sophos]2
Trojan.Agent!sd6 [PC Tools]2
Trojan.Bredolab [PC Tools]2
Trojan.Bredolab [Symantec]2
Trojan.Win32.Agent.asli [Kaspersky Lab]2
Trojan:Win32/Zbot.CJ [Microsoft]2
Trojan-Spy.Win32.Zbot.fnp [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.fvr [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.gan [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.tee [Kaspersky Lab]2
W32/Auraax.worm [McAfee]2
W32/AutoRun-QQ [Sophos]2
Win32/IRCBot.worm.variant [AhnLab]2
Worm.Win32.AutoRun [Ikarus]2
Worm.Win32.AutoRun.pzo [Kaspersky Lab]2
Worm.Win32.AutoRun.qxq [Kaspersky Lab]2
Backdoor.Bifrose [Symantec]1
Backdoor.Bredolab [PC Tools]1
Backdoor.Sdbot [Symantec]1
Bredolab.gen.a [McAfee]1
Downloader.Bancos!gen [Symantec]1
Downloader-ABU [McAfee]1
Email-Worm.Iksmas!sd6 [PC Tools]1
Email-Worm.Win32.Iksmas.bf [Kaspersky Lab]1
FakeAlert-AB.dldr [McAfee]1
Generic Dropper.by [McAfee]1
Generic FakeAlert!co [McAfee]1
Generic FakeAlert!cp [McAfee]1
Generic Packed [McAfee]1
Generic PWS.y [McAfee]1
Generic.dx [McAfee]1
Generic.dx!t [McAfee]1
Mal/Behav-301, Mal/EncPk-CZ [Sophos]1
Mal/Behav-340 [Sophos]1
Mal/Bredo-A [Sophos]1
Mal/Bredo-A, Mal/EncPk-KW [Sophos]1
Mal/Emogen-I, Mal/Behav-043 [Sophos]1
Mal/EncPk-FZ, Mal/EncPk-CZ [Sophos]1
Mal/EncPk-IC [Sophos]1
Mal/EncPk-KP [Sophos]1
Mal/GamePSW-C [Sophos]1
Mal/Waledec-A, Mal/WaledPak-A, Mal/EncPk-EV [Sophos]1
Mal/Zbot-G, Mal/EncPk-CZ [Sophos]1
Mal_Banker [Trend Micro]1
Packed.Generic.233 [Symantec]1
Packed.Generic.265 [Symantec]1
Packed.Win32.Krap.ad [Kaspersky Lab]1
Packed.Win32.Krap.an [Kaspersky Lab]1
PWS:Win32/Zbot.gen!R [Microsoft]1
PWS:Win32/Zbot.VI [Microsoft]1
Troj/Agent-GRA [Sophos]1
Troj/Agent-HRI [Sophos]1
Troj/Agent-HWN [Sophos]1
Troj/Agent-HXB [Sophos]1
Troj/Agent-HYC [Sophos]1
Troj/Agent-HYY [Sophos]1
Troj/Agent-HZB [Sophos]1
Troj/Agent-HZO [Sophos]1
Troj/Agent-HZQ [Sophos]1
Troj/Agent-IDT [Sophos]1
Troj/Agent-IDX [Sophos]1
Troj/Agent-IGP [Sophos]1
Troj/Agent-IKA [Sophos]1
Troj/Agent-IKT [Sophos]1
Troj/Agent-IOU [Sophos]1
Troj/Agent-IPH [Sophos]1
Troj/Agent-JUC [Sophos]1
Troj/Bredo-BF [Sophos]1
Troj/Bredo-BI [Sophos]1
Troj/BredoZp-S [Sophos]1
Troj/Dloadr-BWL [Sophos]1
Troj/Dloadr-CVD [Sophos]1
Troj/Rootkit-EF [Sophos]1
Troj/VB-EJ [Sophos]1
Troj/Zbot-AQ [Sophos]1

Win32.Outbreak [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation17
Brazil1
Germany1
Spain1

Win32.Outbreak [Ikarus] is known to be created as:
%AppData%\seres.exe
%AppData%\svcst.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\microsoft common\wuauclt.exe
%Programs%\startup\isqsys32.exe
%System%\javacc.exe
%System%\mscdexntx.exe
%System%\rs32net.exe
%System%\runwin32\rundll.exe
%System%\sdra64.exe
%System%\systemupdate\lsass.exe
%System%\twext.exe
%System%\win32\svchost.exe
%System%\windowsmsgex\windowsupdate.exe
%Temp%\1.exe
%Temp%\base64.dll
%Temp%\p1.exe
%Temp%\p2.exe
%Windir%\lsass.exe
%Windir%\svchost.com
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.