Threat Search: 

ThreatExpert's Statistics for Virus:Win32/Virut.AP [Microsoft]:

Virus:Win32/Virut.AP [Microsoft] is also known as:
Threat AliasNumber of Incidents
W32/Vetor-A [Sophos]263
PE_VIRUT.XO [Trend Micro]259
Virus.Win32.Virut.q [Kaspersky Lab]254
W32/Virut.gen [McAfee]250
W32.Virut.U [Symantec]241
Win32.Virut.Gen.5 [PC Tools]239
Trojan-Downloader.Win32.VB.bbi [Ikarus]49
Virus.Win32.Sality [Ikarus]18
W32.SillyFDC [Symantec]14
Win32/Virut.D [AhnLab]13
Virus.Win32.Virut [Ikarus]9
Email-Worm.Win32.Runouce.b [Kaspersky Lab]8
PE_Chir.B [Trend Micro]6
W32/Chir.b@MM [McAfee]6
W32/Chir-B [Sophos]6
Generic VB.c [McAfee]5
Virus.Win32.Virut.bo [Ikarus]5
Worm.VB.YVF [PC Tools]5
Worm.Win32.VB.du [Ikarus]5
Email-Worm.Win32.Runouce.B [Ikarus]4
Spam-Mailbot [McAfee]4
Virus.Win32.Virut.ak [Ikarus]4
W32.Spybot.Worm [Symantec]4
Worm.Win32.AutoRun [Ikarus]4
Email-Worm.Win32.Tanatos.B [Ikarus]3
Trojan.Win32.Agent [Ikarus]3
Trojan.Win32.Pakes.cob [Kaspersky Lab]3
Trojan-Dropper.Delf [Ikarus]3
Trojan-Spy.Win32.Banker.RM [Ikarus]3
Virus.Win32.Sality.s [Ikarus]3
Virus.Win32.Virut.q [Ikarus]3
Worm.VB.FMU [PC Tools]3
Backdoor.Win32.Rbot.rqg [Kaspersky Lab]2
Backdoor.Win32.VanBot [Ikarus]2
Email-Worm.Win32.Brontok.A [Ikarus]2
Email-Worm.Win32.Mydoom.bj [Ikarus]2
FakeAlert-AG.gen.c [McAfee]2
JS.Chir.B [PC Tools]2
Mal/Dorf-A [Sophos]2
Mal_Banker [Trend Micro]2
PWS-Gamania.gen.a [McAfee]2
Trojan.Agent.DEL [PC Tools]2
Trojan.Agent.VYJ [PC Tools]2
Trojan.DL.AutoIt.DO [PC Tools]2
Trojan.Dropper [Symantec]2
Trojan.Win32.Agent.aec [Kaspersky Lab]2
Trojan-Banker.Win32.Bancos [Ikarus]2
Trojan-Dropper.Win32.Small.azk [Ikarus]2
Virus.Win32.VB.bg [Ikarus]2
W32.Chir.B@mm [Symantec]2
W32.Mytob@mm [Symantec]2
W32.Rajump [Symantec]2
W32.Svich [Symantec]2
W32/Dref-AW [Sophos]2
W32/Nuwar@MM [McAfee]2
Win32.Virtob.2 [Ikarus]2
Worm.Poebot.FG [PC Tools]2
Worm.VB.AAWD [PC Tools]2
Backdoor.Win32.Breplibot [Ikarus]1
Backdoor.Win32.Refpron [Ikarus]1
BackDoor-DIY [McAfee]1
Downloader [Symantec]1
Downloader.Zlob!gen.3 [Symantec]1
FakeAlert-AR [McAfee]1
IM-Worm.Win32.Sohanad.dz [Kaspersky Lab]1
IM-Worm.Win32.VB.as [Ikarus]1
I-Worm.Brontok.DE [PC Tools]1
Mal/Dorf-E, Mal/Heuri-E [Sophos]1
Net-Worm.Win32.Kolab.vl [Kaspersky Lab]1
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]1
Packer.PrivateExeProtector.A [Ikarus]1
PE_DZAN.A [Trend Micro]1
PE_SALITY.AM [Trend Micro]1
Possible_DLDER [Trend Micro]1
PWS-Banker.gen.aa [McAfee]1
QHosts-77 [McAfee]1
Troj/QHost-AD [Sophos]1
Trojan Horse [Symantec]1
Trojan.Qhost.EU [PC Tools]1
Trojan.Win32.Anomaly.D [Ikarus]1
Trojan.Win32.Crypt.mv [Ikarus]1
Trojan.Win32.Disabler [Ikarus]1
Trojan.Win32.Disabler.i [Kaspersky Lab]1
Trojan.Win32.FakePowav [Ikarus]1
Trojan.Win32.KillAV.iy [Ikarus]1
Trojan.Win32.Pakes [Ikarus]1
Trojan.Win32.Pakes.kgb [Kaspersky Lab]1
Trojan.Win32.Pakes.may [Kaspersky Lab]1
Trojan.Win32.Patched [Ikarus]1
Trojan-Downloader.Win32.AutoIt.aa [Ikarus]1
Trojan-Downloader.Win32.AutoIt.aa [Kaspersky Lab]1
Trojan-Downloader.Win32.Banload [Ikarus]1
Trojan-Downloader.Win32.Small [Ikarus]1
Trojan-Dropper.Agent [Ikarus]1
Trojan-Dropper.Small.axz [PC Tools]1
Trojan-Dropper.Win32.Agent.vvp [Kaspersky Lab]1
Trojan-Dropper.Win32.Cutwail [Ikarus]1
Trojan-Dropper.Win32.Cutwail.AL [Ikarus]1
Trojan-Dropper.Win32.Renos.H [Ikarus]1
Trojan-Dropper.Win32.Vaultac [Ikarus]1

Virus:Win32/Virut.AP [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Netherlands11
United Kingdom7
China6
Italy6
Brazil4
Germany3
Israel3
Russian Federation2
Canada1
France1
Taiwan1
Thailand1
Turkey1

Virus:Win32/Virut.AP [Microsoft] is known to be created as:
%AppData%\%username%.task\services.exe
%AppData%\br6657on.exe
%AppData%\csrss.exe
%AppData%\facegame\facegame.exe
%AppData%\inetinfo.exe
%AppData%\lsass.exe
%AppData%\services.exe
%AppData%\smss.exe
%AppData%\svchost.exe
%AppData%\winlogon.exe
%CommonAppData%\normal.exe
%CommonDesktopDir%\desktop.exe
%CommonPrograms%\programs.exe
%Programs%\startup\ctfmon.exe
%Programs%\startup\scan.com
%System%\0617152d\services.exe
%System%\3361\svchost.exe
%System%\7z.exe
%System%\amvo.exe
%System%\av-prev.exe
%System%\caudio.exe
%System%\ccapps.exe
%System%\ckvo.exe
%System%\cmd-bro-ikx.exe
%System%\cmd-brontok.exe
%System%\codeblocks.exe
%System%\controls.exe
%System%\cpl32ver.exe
%System%\dllcache\regedit32.com
%System%\dllcache\shell32.com
%System%\dllcache\zipexr.dll
%System%\dllchache.exe
%System%\dxblat.exe
%System%\exerun.exe
%System%\ex-plorer.exe
%System%\f41\svchost.exe
%System%\flashy.exe
%System%\gassoocyw.exe
%System%\loloxz\smss.exe
%System%\m5vbvm60.exe
%System%\mmdmm.exe
%System%\myrer.exe
%System%\reader.exe
%System%\reader_s.exe
%System%\rs32net.exe
%System%\rund1132.exe
%System%\rvhost.exe
%System%\soundmix.exe
%System%\ssvichosst.exe
%System%\startup\scan.com
%System%\startup\scvhost.exe
%System%\sysnet.exe
%System%\update32.exe
%System%\v6msn.exe
%System%\winsit.exe
%Temp%\0005d3b3_rar\scvhosts.exe
%Temp%\ayra.exe
%Temp%\lsass.exe
%Templates%\11496-nendangbro.com
%Templates%\winword.exe
%Templates%\winword2.exe
%UserProfile%\reader_s.exe
%Windir%\aragpren.exe
%Windir%\dc.exe
%Windir%\dhcp\svchost.exe
%Windir%\exeserv.exe
%Windir%\help\other.exe
%Windir%\help\schedl.exe
%Windir%\inf\other.exe
%Windir%\kesenjangansosial.exe
%Windir%\neos.exe
%Windir%\rvhost.exe
%Windir%\sembako-cnzjkij.exe
%Windir%\services.exe
%Windir%\shellnew\bbm-rpokijnc.exe
%Windir%\shellnew\rakyatkelaparan.exe
%Windir%\ssvichosst.exe
%Windir%\svchost.exe
%Windir%\sviq.exe
%Windir%\sys1.exe
%Windir%\system\fun.exe
%Windir%\system\svchost.exe
%Windir%\system\winexec.com
%Windir%\system32.exe
%Windir%\twain.exe
%Windir%\vmmreg32.exe
%Windir%\windows.exe
%Windir%\winlog.com
%Windir%\xmss.exe
c:\autoexec.exe
c:\b.com
c:\c.exe
c:\explorer.exe
c:\inetpub\inetpub.exe
c:\joniezz.exe
c:\ravmon.exe
c:\recycled\ctfmon.exe
c:\recycled\recycled\ctfmon.exe
c:\recycled\smss.exe
c:\recycled\spoolsv.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Templates% is a variable that refers to the file system directory that serves as a common repository for document templates. A typical path is C:\Documents and Settings\[UserName]\Templates.
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.