Threat AliasNumber of Incidents
PE_VIRUT.AT [Trend Micro]95
W32/Virut.gen.a [McAfee]85
Win32.Virut.Gen.4 [PC Tools]72
Virus:Win32/Virut.AA [Microsoft]47
W32/Virut-Gen [Sophos]45
W32.Virut.W [Symantec]39
Win32/Virut [AhnLab]34
Bloodhound.Unknown [Symantec]10
W32.IRCBot [Symantec]9
Mal/HckPk-A, W32/Virut-Gen [Sophos]6
Virus.Win32.Virut.n [Ikarus]6
W32/RAHack [McAfee]4
Backdoor.SdBot [PC Tools]3
Backdoor.Sdbot [Symantec]3
Packer.RLPack [Ikarus]3
Trojan.Win32.Qhost.aei [Ikarus]3
Virus.Win32.Rizo.E [Ikarus]3
Virus.Win32.Sality [Ikarus]3
Virus.Win32.Virut [Ikarus]3
W32.Spybot.Worm [Symantec]3
W32/Virut.j [McAfee]3
Worm.Win32.Neeris [Ikarus]3
Worm:Win32/Neeris.AN [Microsoft]3
Backdoor.Trojan [Symantec]2
Backdoor.VanBot.CL [PC Tools]2
Backdoor:Win32/Poebot.AT [Microsoft]2
Mal/TinyDL-T, Mal/HckPk-A, W32/Virut-Gen [Sophos]2
Packer.RLPack.D [Ikarus]2
Trojan-Dropper.Win32.Delf [Ikarus]2
Trojan-Proxy.Win32.Slaper.n [Ikarus]2
Worm.Allaple.AA [PC Tools]2
Worm.Poebot.IT [PC Tools]2
Adware.Relevant.A [PC Tools]1
Backdoor.Bot [Ikarus]1
Backdoor.Win32.VanBot [Ikarus]1
Backdoor:Win32/Poebot.BA [Microsoft]1
Backdoor:Win32/Poebot.BD [Microsoft]1
Generic BackDoor [McAfee]1
Mal/EncPk-BW, W32/Virut-Gen [Sophos]1
Mal/Generic-A, W32/Virut-Gen [Sophos]1
Mal/MDrop-Gen, W32/Virut-Gen [Sophos]1
Net-Worm.Win32.Allaple.a [Ikarus]1
Net-Worm.Win32.Kolabc [Ikarus]1
New Win32 [McAfee]1
Spam-Mailbot [McAfee]1
Spyware.Marketscore_Netsetter [PC Tools]1
Trojan.DL.Small.WJH [PC Tools]1
Trojan.PR.Ranky.FP [PC Tools]1
Trojan.Win32.Inject [Ikarus]1
Trojan-Downloader.Win32.Small [Ikarus]1
Trojan-Dropper.Win32.Microjoin [Ikarus]1
Virus:Win32/Lurka.A [Microsoft]1
Virus:Win32/Virut.D [Microsoft]1
W32.Rahack.H [Symantec]1
W32.SillyFDC [Symantec]1
W32/Lurka.a [McAfee]1
W32/Lurka-A [Sophos]1
W32/Virut-L [Sophos]1
Worm.Poebot.IN [PC Tools]1
Worm.Poebot.KC [PC Tools]1
Worm.PoeBot.KY [PC Tools]1
Worm.VB.VLL [PC Tools]1
Worm.Win32.VB.cj [Ikarus]1
Worm:Win32/Wootbot.EG [Microsoft]1 [Kaspersky Lab] has the following possible countries of origin:
OriginNumber of Incidents
Turkey1 [Kaspersky Lab] is known to be created as:
%ProgramFiles%\common files\system\msasp32.exe
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.