Threat Search: 

ThreatExpert's Statistics for IM-Worm.Win32.Agent [Ikarus]:

IM-Worm.Win32.Agent [Ikarus] is also known as:
Threat AliasNumber of Incidents
Win32/Agent.worm.991248 [AhnLab]15
Trojan:Win32/Nuwvult.A [Microsoft]14
Mal/Generic-A [Sophos]6
Trojan Horse [Symantec]2
Worm:Win32/Failnum.A [Microsoft]2
Adware.Gen [Symantec]1
Generic BackDoor.bx [McAfee]1
Generic.dx!cfe [McAfee]1
Generic.dx!dx [McAfee]1
Generic.dx!ie [McAfee]1
Generic.dx!js [McAfee]1
IM-Worm.Win32.Agent.md [Kaspersky Lab]1
IM-Worm.Win32.Agent.nd [Kaspersky Lab]1
IM-Worm.Win32.Agent.nv [Kaspersky Lab]1
IM-Worm.Win32.Agent.nw [Kaspersky Lab]1
IM-Worm.Win32.Agent.pm [Kaspersky Lab]1
IM-Worm.Win32.Agent.ql [Kaspersky Lab]1
IM-Worm.Win32.Agent.sg [Kaspersky Lab]1
Malware.Fnumbot [PC Tools]1
Trojan.Adclicker [PC Tools]1
Trojan.Adclicker [Symantec]1
W32.Fnumbot [Symantec]1
W32.SillyFDC [Symantec]1
W32/Autorun.worm.c [McAfee]1
W32/Autorun-AVF [Sophos]1
W32/YahLover.worm [McAfee]1
Win32/Agent.worm.80896.B [AhnLab]1
Win32/IMStealer.worm.76288 [AhnLab]1

IM-Worm.Win32.Agent [Ikarus] has the following possible country of origin:
OriginNumber of Incidents
Slovenia1

IM-Worm.Win32.Agent [Ikarus] is known to be created as:
%System%\advhost.exe
%Temp%\vshost32.exe
c:\vshost.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).