Threat Search: 

ThreatExpert's Statistics for Worm:Win32/Pushbot.gen!C [Microsoft]:

Worm:Win32/Pushbot.gen!C [Microsoft] is also known as:
Threat AliasNumber of Incidents
W32.IRCBot.Gen [Symantec]28
New Malware.b [McAfee]23
Suspicious.MH690 [Symantec]22
Win32/IRCBot.worm.Gen [AhnLab]22
Backdoor.Win32.IRCBot.gen [Kaspersky Lab]21
Generic QHosts.a.gen [McAfee]19
W32.Spybot.Worm [Symantec]18
Backdoor.Win32.IRCBot [Ikarus]17
Trojan.Win32.Qhost.cm [Kaspersky Lab]16
Mal/Generic-A [Sophos]14
Worm.Win32.Pushbot [Ikarus]14
W32.IRCBot [Symantec]13
W32/Checkout [McAfee]13
Virus.Win32.IRCBot.BSX [Ikarus]12
Trojan.QHosts.AA [PC Tools]11
Mal/IRCBot-B [Sophos]10
W32.Netsky.gen@mm [Symantec]10
VirTool.Win32.DelfInject [Ikarus]9
Trojan.QHosts.G [PC Tools]6
W32/Generic.b.worm [McAfee]6
W32/Sdbot.worm [McAfee]6
Worm.Win32.AutoRun.mcp [Kaspersky Lab]6
Mal/Behav-285 [Sophos]5
Mal/EncPK-LL [Sophos]5
Mal/IRCBot-B, Mal/Behav-150 [Sophos]5
Mal/SillyFDC-A, Mal/Behav-150 [Sophos]5
Suspicious.Skintrim [Symantec]5
Virus.Win32.IRCBot [Ikarus]5
W32/Sdbot.worm.gen.ci [McAfee]5
Win32/IRCBot.worm.variant [AhnLab]5
WORM_SDBOT.GAV [Trend Micro]5
Backdoor.Win32.SdBot [Ikarus]4
Exploit-DcomRpc.gen [McAfee]4
Mal/SillyFDC-A [Sophos]4
Mal/SillyFDC-A, Mal/IRCBot-B [Sophos]4
Mal/SillyFDC-A, Mal/IRCBot-B, Mal/IRCBot-C [Sophos]4
Packed.Win32.Black [Ikarus]4
Trojan.Win32.Buzus.alvq [Kaspersky Lab]4
WORM_RBOT.GEN [Trend Micro]4
Backdoor.Win32.Wootbot.gep [Kaspersky Lab]3
Constructor.Win32.Binder [Ikarus]3
Mal/EncPk-JU [Sophos]3
Packed.Win32.Black.a [Kaspersky Lab]3
Trojan.IRCBot [PC Tools]3
W32/Autorun.worm.gen [McAfee]3
Win-Trojan/Buzus.390656.E [AhnLab]3
Worm.RBot.Gen.16 [PC Tools]3
Backdoor.Rbot [Ikarus]2
Backdoor.Win32.Bifrose [Ikarus]2
Downloader.gen.a [McAfee]2
Email-Worm.Netsky!sd6 [PC Tools]2
IRC Trojan [Symantec]2
Mal/Behav-024, Mal/SillyFDC-A [Sophos]2
Mal/Dorf-A [Sophos]2
Net-Worm.Win32.Kolab [Ikarus]2
Net-Worm.Win32.Mytob [Ikarus]2
Troj/WootBt-Gen [Sophos]2
Trojan Horse [Symantec]2
Trojan.Crypt [Ikarus]2
Virus.Win32.Agent.JBM [Ikarus]2
W32.Mytob@mm [Symantec]2
W32.SillyFDC [Symantec]2
W32/Checkout!n [McAfee]2
W32/Mytob.gen@MM [McAfee]2
Win32/Mytob.worm.69632.C [AhnLab]2
Win32/Mytob.worm.69632.D [AhnLab]2
Worm.Win32.AutoRun [Ikarus]2
Adware.Gen [PC Tools]1
Adware.Gen [Symantec]1
Backdoor.IRCBot!ct [PC Tools]1
Backdoor.IRCBot.a.gen [PC Tools]1
Backdoor.IRCBot.GEN [PC Tools]1
Backdoor.Trojan [PC Tools]1
Backdoor.Trojan [Symantec]1
Backdoor.Win32.DsBot.jm [Kaspersky Lab]1
Backdoor.Win32.IRCBot.dhr [Kaspersky Lab]1
Backdoor.Win32.Rbot.acdi [Kaspersky Lab]1
Backdoor.Win32.SdBot.miz [Kaspersky Lab]1
Backdoor.Win32.SdBot.nlg [Kaspersky Lab]1
Bloodhound.W32.1 [Symantec]1
Email-Worm.Mytob!sd6 [PC Tools]1
Generic.dx!rl [McAfee]1
Infostealer.Gampass [Symantec]1
Mal/Behav-150 [Sophos]1
Mal/Behav-204 [Sophos]1
Mal/Emogen-N, Mal/IRCBot-B [Sophos]1
Mal/Emogen-N, Mal/IRCBot-B, Mal/SillyFDC-A [Sophos]1
Mal/EncPk-EE [Sophos]1
Mal/IRCBot-B, Mal/SillyFDC-A [Sophos]1
Mal/UnkPack-Fam [Sophos]1
Net-Worm.Win32.Kolab.dqp [Kaspersky Lab]1
Net-Worm.Win32.Kolab.fkt [Kaspersky Lab]1
Net-Worm.Win32.Kolab.fti [Kaspersky Lab]1
Net-Worm.Win32.Mytob.gge [Kaspersky Lab]1
Net-Worm.Win32.Mytob.ggm [Kaspersky Lab]1
Net-Worm.Win32.Mytob.gje [Kaspersky Lab]1
Net-Worm.Win32.Mytob.glv [Kaspersky Lab]1
New Malware.cj [McAfee]1
New Malware.dq [McAfee]1
not-a-virus:FraudTool.Win32.SpyLocked [Ikarus]1

Worm:Win32/Pushbot.gen!C [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Israel2
Germany1
Macedonia1
Turkey1

Worm:Win32/Pushbot.gen!C [Microsoft] is known to be created as:
%AppData%\cftmon.exe
%AppData%\intranetexplorer.exe
%AppData%\shieldmanager.exe
%AppData%\update.exe
%FontsDir%\msnmsgn.exe
%ProgramFiles%\common files\system\klass.exe
%System%\dllcache\nlsvc32.exe
%System%\hpdrv.exe
%System%\instaler.exe
%System%\msnrmgs.exe
%System%\runtime.exe
%System%\tskmngr.exe
%Temp%\120.exe
%Temp%\2.exe
%Temp%\480045.exe
%Temp%\decrypted.exe
%Temp%\imbot.exe
%Temp%\ixp000.tmp\netw.exe
%Temp%\nesbot.exe
%Temp%\nsb3.tmp\dumpo.exe
%Temp%\octomom.exe
%Temp%\server.exe
%Windir%\cftmon.exe
%Windir%\ctfm.exe
%Windir%\explors.exe
%Windir%\imbot18.exe
%Windir%\ituneshelp.exe
%Windir%\k8svr.exe
%Windir%\lsass32.exe
%Windir%\msagent\svhost.exe
%Windir%\nero3.exe
%Windir%\nod32.exe
%Windir%\sccvhost.exe
%Windir%\scvhost.exe
%Windir%\server.exe
%Windir%\service.exe
%Windir%\servicemsn.exe
%Windir%\services.exe
%Windir%\svchoste.exe
%Windir%\svchosts.exe
%Windir%\svhost.exe
%Windir%\svrse.exe
%Windir%\system.exe
%Windir%\system\msvc32s.exe
%Windir%\twunk_48.exe
%Windir%\windirs.exe
%Windir%\winlogon.exe
%Windir%\winsvc.exe
%Windir%\winsvc32.exe
%Windir%\wkssvr.exe
%Windir%\wkssxr.exe
%Windir%\wscntfys.exe
%Windir%\yah00-messenger.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.