Threat Search: 

ThreatExpert's Statistics for Virus.Win32.Virut.au [Ikarus]:

Virus.Win32.Virut.au [Ikarus] is also known as:
Threat AliasNumber of Incidents
Mal/EncPk-EQ [Sophos]76
TrojanDownloader:Win32/FakeRean [Microsoft]41
Trojan.Virantix.C [Symantec]40
W32.Virut.W [Symantec]39
Virus:Win32/Virut.AU [Microsoft]34
W32/Virut-Gen [Sophos]33
PE_VIRUT.BA [Trend Micro]32
Virus.Win32.Virut.bx [Kaspersky Lab]32
W32/Virut.j [McAfee]31
Generic Dropper.bu [McAfee]27
TrojanDownloader:Win32/Renos [Microsoft]27
TrojanDownloader:Win32/FakeRean.gen!C [Microsoft]20
Generic FakeAlert.d [McAfee]18
Trojan.Virantix!sd6 [PC Tools]16
FakeAlert-XPSecCenter [McAfee]14
Downloader.MisleadApp [Symantec]13
Troj/FakeAle-JI [Sophos]9
Trojan.Win32.FraudPack.gtt [Kaspersky Lab]9
W32/Vetor-A [Sophos]9
Adware.Agent.ZO [PC Tools]8
AntiVirus2009 [Symantec]8
Trojan-Downloader.Win32.FakeRean [Ikarus]8
Trojan:Win32/Wantvi.I [Microsoft]7
Trojan-Downloader.Win32.FraudLoad.vdii [Kaspersky Lab]7
Win32.Virut.Gen.4 [PC Tools]7
Win32/Virut.Gen [AhnLab]7
not-a-virus:FraudTool.Win32.XPAntiSpyware2009.i [Kaspersky Lab]6
W32.Virut.U [Symantec]6
Win32.Virut.Gen.5 [PC Tools]6
PE_VIRUT.XP [Trend Micro]5
Trojan.Virantix [Symantec]5
Virus.Win32.Virut.q [Kaspersky Lab]5
Virus:Win32/Virut.AE [Microsoft]5
Hoax.Win32.Renos.fef [Kaspersky Lab]4
RogueAntiSpyware.AntiVirusPro [PC Tools]4
Troj/FakeAle-JK [Sophos]4
Trojan.Win32.Agent.apwo [Kaspersky Lab]4
Virus.Win32.Virut.n [Kaspersky Lab]4
W32/Virut.gen.a [McAfee]4
Generic FakeAlert.a [McAfee]3
PE_VIRUT.D [Trend Micro]3
Trojan.Win32.Pakes.lnh [Kaspersky Lab]3
Trojan:Win32/FakeRean [Microsoft]3
Virus:Win32/Virut.AK [Microsoft]3
W32.Virut.B [Symantec]3
Win32.Virut.Gen [PC Tools]3
Win32/Virut.B [AhnLab]3
Infostealer [Symantec]2
New Win32 [McAfee]2
PE_VIRUT.PAU [Trend Micro]2
PE_VIRUT.XV [Trend Micro]2
PE_VIRUT.YE [Trend Micro]2
Virus.Win32.Virut.ac [Kaspersky Lab]2
Virus.Win32.Virut.af [Kaspersky Lab]2
Virus.Win32.Virut.y [Kaspersky Lab]2
Virus:Win32/Virut.Q [Microsoft]2
Virus:Win32/Virut.T [Microsoft]2
Virus:Win32/Virut.V [Microsoft]2
W32/Vetor-G [Sophos]2
W32/Virut.h [McAfee]2
W32/Virut-V [Sophos]2
Backdoor.UltimateDefender!sd6 [PC Tools]1
Backdoor.Win32.UltimateDefender.gjb [Kaspersky Lab]1
Backdoor.Win32.UltimateDefender.gjz [Kaspersky Lab]1
Downloader [Symantec]1
Generic PUP.x [McAfee]1
Generic PWS.ak [McAfee]1
PE_VIRUT.XL [Trend Micro]1
PE_VIRUT.XW [Trend Micro]1
PE_VIRUT.XZ [Trend Micro]1
Qhost-Gen [McAfee]1
Troj/FakeAle-JF [Sophos]1
Troj/FakeAle-JJ [Sophos]1
Trojan.Dropper [Symantec]1
Trojan.Win32.StartPage.dgv [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.vdho [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.vmey [Kaspersky Lab]1
TrojanDropper:Win32/Renos [Microsoft]1
Virus.Win32.Virut.ah [Kaspersky Lab]1
Virus.Win32.Virut.ai [Kaspersky Lab]1
Virus:Win32/Sality.AM [Microsoft]1
Virus:Win32/Virut.AF [Microsoft]1
Virus:Win32/Virut.gen!AI [Microsoft]1
W32/Virut [McAfee]1
W32/Virut-S [Sophos]1
Win-Trojan/Fakeav.9728 [AhnLab]1
Worm.PoeBot.LA [PC Tools]1

Virus.Win32.Virut.au [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation88
China1
Finland1
France1
Iran1
Saudi Arabia1

Virus.Win32.Virut.au [Ikarus] is known to be created as:
%ProgramFiles%\antispywarexp2009\uninstall.exe
%ProgramFiles%\antiviruspro2009\uninstall.exe
%ProgramFiles%\uninstall.exe
%ProgramFiles%\xp_antispyware\uninstall.exe
%System%\amvo.exe
%System%\brastk.exe
%System%\firewall.exe
%System%\logon.exe
%System%\olhrwef.exe
%System%\reader.exe
%System%\reader_s.exe
%System%\rs32net.exe
%Temp%\wini10491.exe
%UserProfile%\reader_s.exe
%Windir%\rbsbbrra.exe
%Windir%\services.exe
c:\e8kj.exe
c:\ms-dos\ntdlr.com
c:\smss.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.