Threat Search: 

ThreatExpert's Statistics for Email-Worm.Win32.Runouce [Ikarus]:

Email-Worm.Win32.Runouce [Ikarus] is also known as:
Threat AliasNumber of Incidents
Email-Worm.Win32.Runouce.b [Kaspersky Lab]136
W32/Chir.b@MM [McAfee]124
W32/Chir-B [Sophos]124
W32.Chir.B@mm [Symantec]115
Virus:Win32/Chir.B@mm [Microsoft]110
I-Worm.Chir.B [PC Tools]88
PE_Chir.B-O [Trend Micro]79
Win32/ChiHack.worm.10748 [AhnLab]68
PE_Chir.B [Trend Micro]45
Win32/ChiHack.6652 [AhnLab]45
Email-Worm.Runouce!sd5 [PC Tools]8
JS.Chir.B [PC Tools]5
Worm.AutoIT.V [PC Tools]5
Email-Worm.Runonce!ct [PC Tools]4
Generic.dx [McAfee]4
Mal/Generic-A [Sophos]4
Virus:Win32/Virut.K [Microsoft]4
W32/Virut.gen [McAfee]4
Win32.Virut.Gen.5 [PC Tools]4
Worm:Win32/Chir.D@mm [Microsoft]4
Email-Worm.Win32.Runouce.B [Ikarus]3
W32.SillyDC [Symantec]3
Win32/Virut.D [AhnLab]3
PE_SALITY.AL-1 [Trend Micro]2
PE_VIRUT.XP [Trend Micro]2
Virus.Win32.Virut.ce [Kaspersky Lab]2
Virus:Win32/Sality.AM [Microsoft]2
Virus:Win32/Sality.T [Microsoft]2
Virus:Win32/Virut.BM [Microsoft]2
Virus:Win32/Virut.D [Microsoft]2
W32.Sality.AE [Symantec]2
W32.Sality.X [Symantec]2
W32.SillyFDC [Symantec]2
W32.Virut.CF [Symantec]2
W32.Virut.U [Symantec]2
W32/Sality.gen [McAfee]2
W32/Sality.z [McAfee]2
W32/Sality-AD [Sophos]2
W32/Sality-AM [Sophos]2
W32/Scribble-B [Sophos]2
W32/Vetor-A [Sophos]2
Win32.Sality.AA [PC Tools]2
Win32.Virut.Gen [PC Tools]2
Win32/Kashu.B [AhnLab]2
Win32/Sality.K [AhnLab]2
Win32/Virut.F [AhnLab]2
Mal/Sality-C [Sophos]1
New Win32 [McAfee]1
PE_CHIR.DAM [Trend Micro]1
PE_SALITY.AZ [Trend Micro]1
PE_SALITY.EN [Trend Micro]1
PE_SALITY.EN-1 [Trend Micro]1
PE_VIRUT.XS [Trend Micro]1
PE_VIRUT.YE [Trend Micro]1
Trojan.DL.AutoIt.DO [PC Tools]1
Virus.Sality.ae [PC Tools]1
Virus.Win32.Sality.aa [Kaspersky Lab]1
Virus.Win32.Sality.ae [Kaspersky Lab]1
Virus.Win32.Virut.ae [Kaspersky Lab]1
Virus.Win32.Virut.n [Kaspersky Lab]1
Virus.Win32.Virut.q [Kaspersky Lab]1
Virus:Win32/Sality.AN [Microsoft]1
Virus:Win32/Virut.AE [Microsoft]1
Virus:Win32/Virut.P [Microsoft]1
W32.Imaut [Symantec]1
W32.Sality.AM [Symantec]1
W32.Virut.H [Symantec]1
W32/Chir.gen@MM!remanants [McAfee]1
W32/Sality.gen.c [McAfee]1
W32/SillyFDC-AP [Sophos]1
W32/Vetor-G [Sophos]1
W32/Virut.i [McAfee]1
W32/Virut.n [McAfee]1
W32/Virut-L [Sophos]1
Win32.Virut.Gen.4 [PC Tools]1
Win32/Kashu.C [AhnLab]1
Win32/Virut.B [AhnLab]1

Email-Worm.Win32.Runouce [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
United Kingdom8
Brazil7
China2
Czech Republic1
France1
Germany1
Israel1
Russian Federation1
Spain1
Taiwan1

Email-Worm.Win32.Runouce [Ikarus] is known to be created as:
%CommonPrograms%\startup\java7.exe
%ProgramFiles%\bifrost\server.exe
%System%\gbpsv.exe
%System%\msmsgs.exe
%System%\pes.exe
%System%\reader_s.exe
%System%\runouce.exe
%System%\ssvichosst.exe
%System%\svrchost.exe
%System%\winrar\winrar.exe
%Temp%\0005a59e_rar\msmsgs.exe
%Temp%\0005d1ce_rar\msmsgs.exe
%Temp%\bb5logger.exe
%Temp%\genielogger.exe
%UserProfile%\reader_s.exe
%UserProfile%\saluko.exe
%Windir%\ssvichosst.exe
%Windir%\svrchost.exe
Notes:
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.