Threat Search: 

ThreatExpert's Statistics for Virus:Win32/Chir.B@mm [Microsoft]:

Virus:Win32/Chir.B@mm [Microsoft] is also known as:
Threat AliasNumber of Incidents
W32/Chir.b@MM [McAfee]578
Email-Worm.Win32.Runouce.b [Kaspersky Lab]574
W32/Chir-B [Sophos]571
W32.Chir.B@mm [Symantec]485
PE_Chir.B-O [Trend Micro]317
I-Worm.Chir.B [PC Tools]308
PE_Chir.B [Trend Micro]257
JS.Chir.B [PC Tools]168
Email-Worm.Win32.Runouce.B [Ikarus]164
Email-Worm.Win32.Runouce [Ikarus]110
Win32/ChiHack.worm.10748 [AhnLab]97
Win32/ChiHack.6652 [AhnLab]88
W32.Rontokbro.X@mm [Symantec]47
Email-Worm.Win32.Brontok.N [Ikarus]28
Worm.Brontok.Gen!Pac.3 [PC Tools]27
Email-Worm.Runouce!sd5 [PC Tools]16
W32.SillyFDC [Symantec]16
Email-Worm.Runonce!ct [PC Tools]8
Backdoor.Win32.Bifrose [Ikarus]6
Backdoor.Bifrose.EZC [PC Tools]5
Trojan.Crypt [Ikarus]5
Worm.AutoIT.V [PC Tools]5
Worm.Win32.VB.cj [Ikarus]5
PE_CHIR.DAM [Trend Micro]4
Trojan.Win32.VB [Ikarus]4
Trojan-Banker.Win32.Banker [Ikarus]4
Virus.Win32.Bifrose [Ikarus]4
W32.Rajump [Symantec]4
W32.SillyDC [Symantec]4
W32/Scribble-B [Sophos]4
W32/Virut.n.gen [McAfee]4
Trojan.Autoit [Ikarus]3
Trojan.Win32.Agent [Ikarus]3
Trojan.Win32.Midgare [Ikarus]3
Trojan-Dropper.Delf [Ikarus]3
Virus.Win32.AutoRun.vc [Ikarus]3
Virus.Win32.Hakaglan [Ikarus]3
W32.Dizan [Symantec]3
W32.Rontokbro@mm [Symantec]3
Email-Worm.Chir [PC Tools]2
Generic VB.b [McAfee]2
Trojan.Agent.VYJ [PC Tools]2
Trojan.Midgare.hhn [PC Tools]2
Trojan-Downloader.Win32.Small [Ikarus]2
Virus.Win32.KillFiles.058 [Ikarus]2
W32.Blastclan [Symantec]2
W32.Imaut [Symantec]2
W32.Imaut.N [Symantec]2
W32.Redlofwen [Symantec]2
Win32.Sality.AA.Gen [PC Tools]2
Win32.Virut.Gen.4 [PC Tools]2
Worm.Hakaglan.B [PC Tools]2
Worm.VB.VLL [PC Tools]2
Worm.VB.WKJ [PC Tools]2
Worm.Win32.VB.cz [Ikarus]2
WORM_VB.CIU [Trend Micro]2
Backdoor.Win32.Beastdoor [Ikarus]1
Email-Worm.Win32.Brontok.A [Ikarus]1
Email-Worm.Win32.Generic [Ikarus]1
Email-Worm.Win32.Womble.i [Ikarus]1
Generic.dx [McAfee]1
Infostealer.QQRob.A [Symantec]1
I-Worm.Brontok.ER [PC Tools]1
I-Worm.Rays.F [PC Tools]1
I-Worm.Womble.B1 [PC Tools]1
Mal/VBWorm-C [Sophos]1
Mal/VBWorm-C, W32/Chir-B [Sophos]1
P2P-Worm.Win32.SpyBot [Ikarus]1
PE_VIRUT.XS [Trend Micro]1
Trojan.Agent.ECMZ [PC Tools]1
Trojan.Astry [Symantec]1
Trojan.Banker.Delf.YKG [Ikarus]1
Trojan.DL.AutoIt.DO [PC Tools]1
Trojan.DL.Small.MV [PC Tools]1
Trojan.DR.CKSPost.C [PC Tools]1
Trojan.DR.Small.MV [PC Tools]1
Trojan.Hider.G [PC Tools]1
Trojan.VB.EPP [PC Tools]1
Trojan.VB.XYJ [PC Tools]1
Trojan.VB.YDS [PC Tools]1
Trojan.VB.ZBW [PC Tools]1
Trojan.Win32.VB.atg [Kaspersky Lab]1
Trojan-Dropper.Agent [Ikarus]1
Trojan-Dropper.Vb.1 [Ikarus]1
Trojan-Dropper.Win32.Delf [Ikarus]1
Trojan-PWS.Win32.OnLineGames [Ikarus]1
Trojan-Spy.Win32.Agent.bcm [Ikarus]1
Trojan-Spy.Win32.Ardamax [Ikarus]1
Trojan-Spy.Win32.Banbra [Ikarus]1
Trojan-Spy.Win32.Webmoner [Ikarus]1
VirTool.Win32.DelfInject [Ikarus]1
Virus.W32.Sality [Ikarus]1
Virus.Win32.Agent.OYJ [Ikarus]1
Virus.Win32.AutoRun.jq [Ikarus]1
Virus.Win32.Downloader.BVK [Ikarus]1
Virus.Win32.FakeAlert.S [Ikarus]1
Virus.Win32.Folcom.b [Kaspersky Lab]1
Virus.Win32.Texel.i [Kaspersky Lab]1
Virus.Win32.VB.bb [Ikarus]1
Virus.Win32.VB.KZ [Ikarus]1

Virus:Win32/Chir.B@mm [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
United Kingdom26
China14
Brazil11
Sweden9
Taiwan3
Germany2
Iran2
Russian Federation2
Spain2
Australia1
Czech Republic1
Israel1
Netherlands1
Philippines1
Turkey1

Virus:Win32/Chir.B@mm [Microsoft] is known to be created as:
%AppData%\csrss.exe
%AppData%\dv6173880x\yesbron.com
%AppData%\inetinfo.exe
%AppData%\jalak-931738815-bali.com
%AppData%\lsass.exe
%AppData%\services.exe
%AppData%\smss.exe
%AppData%\winlogon.exe
%CommonPrograms%\startup\avg.exe
%CommonPrograms%\startup\java7.exe
%CommonPrograms%\startup\lsass.exe
%FontsDir%\84baa.com
%FontsDir%\fonts.exe
%FontsDir%\tskmgr.exe
%ProgramFiles%\%stemp%\bifrost.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\explorer.exe
%ProgramFiles%\skype\skype.exe
%ProgramFiles%\utorrent\utorrent.exe
%System%\1025.exe
%System%\1028.exe
%System%\1031.exe
%System%\1033.exe
%System%\1037.exe
%System%\1041.exe
%System%\1042.exe
%System%\1054.exe
%System%\2052.exe
%System%\3076.exe
%System%\3com_dmi.exe
%System%\440510867205l.exe
%System%\662832100427l.exe
%System%\bifrost\server.exe
%System%\blastclnnn.exe
%System%\c_44292k.com
%System%\catroot.exe
%System%\catroot2.exe
%System%\ckvo.exe
%System%\com.exe
%System%\config.exe
%System%\ctoolbar.exe
%System%\dhcp.exe
%System%\directx.exe
%System%\dllcache\default.exe
%System%\dllcache\global.exe
%System%\dllcache\svchost.exe
%System%\drivers.exe
%System%\drivers\drivers.cab.exe
%System%\export.exe
%System%\gbpsv.exe
%System%\ias.exe
%System%\icsxml.exe
%System%\ime.exe
%System%\inetsrv.exe
%System%\instaler.exe
%System%\isass.exe
%System%\macromed.exe
%System%\microsoft.exe
%System%\msdtc.exe
%System%\msmsgs.exe
%System%\mui.exe
%System%\n7533\b8682.exe
%System%\n7533\csrss.exe
%System%\n7533\lsass.exe
%System%\n7533\services.exe
%System%\n7533\smss.exe
%System%\n7533\sv711738830r.exe
%System%\n7533\winlogon.exe
%System%\n8127\smss.exe
%System%\npp.exe
%System%\ntmsdata.exe
%System%\oobe.exe
%System%\ras.exe
%System%\reader_s.exe
%System%\regedit.exe
%System%\regsvr.exe
%System%\reinstallbackups.exe
%System%\restore.exe
%System%\runouce.exe
%System%\rvhost.exe
%System%\scvhost.exe
%System%\scvhosts.exe
%System%\scvhsot.exe
%System%\scvvhsot.exe
%System%\setup.exe
%System%\shellext.exe
%System%\spool.exe
%System%\ssvichosst.exe
%System%\svrchost.exe
%System%\system\system.exe
%System%\usmt.exe
%System%\wbem.exe
%System%\wins.exe
%System%\winsit.exe
%System%\xircom.exe
%Temp%\0005a59e_rar\msmsgs.exe
%Temp%\0005a5dc_rar\scvhosts.exe
%Temp%\0005d1ce_rar\msmsgs.exe
%Temp%\0005d299_rar\scvhosts.exe
%Temp%\0005d374_rar\blastclnnn.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).