Threat Search: 

ThreatExpert's Statistics for Virus:Win32/Virut.BM [Microsoft]:

Virus:Win32/Virut.BM [Microsoft] is also known as:
Threat AliasNumber of Incidents
W32.Virut.CF [Symantec]2,830
Virus.Win32.Virut.ce [Kaspersky Lab]2,718
W32/Scribble-B [Sophos]2,324
Win32/Virut.F [AhnLab]1,841
W32/Virut.n.gen [McAfee]1,612
Win32/Virut.E [AhnLab]639
Malware.Virut [PC Tools]410
New Win32 [McAfee]331
W32/Virut.n [McAfee]311
W32/Scribble-A [Sophos]297
New Win32.g4 [McAfee]120
Virus.Win32.Sality [Ikarus]115
PE_VIRUX.H-3 [Trend Micro]109
Virus.Win32.Virut [Ikarus]107
Mal/HckPk-A, W32/Scribble-B [Sophos]77
New Poly Win32 [McAfee]69
Virus.Win32.Bifrose [Ikarus]54
PE_VIRUX.E-2 [Trend Micro]46
PE_VIRUX.A-1 [Trend Micro]44
Mal/Bifrose-S, W32/Scribble-B [Sophos]40
Virus.Win32.Virut.bo [Ikarus]36
PE_VIRUX.A [Trend Micro]34
PE_VIRUX.E-3 [Trend Micro]34
Trojan-Downloader.Win32.Agent.czsd [Kaspersky Lab]32
Trojan-Banker.Win32.Bancos [Ikarus]31
Spam-Mailbot [McAfee]29
BackDoor-CEP.gen.au [McAfee]24
Backdoor.Rbot [Ikarus]22
W32/Sdbot.worm.gen.g [McAfee]22
WORM_RBOT.GEN-1 [Trend Micro]22
Virus.Virut.j [PC Tools]21
W32/Rbot-Fam, W32/Scribble-B [Sophos]21
Worm.Akbot.Gen [PC Tools]21
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]19
Trojan.Win32.Banker [Ikarus]19
Trojan-Downloader.Win32.Cutwail [Ikarus]18
Backdoor.Win32.Popwin [Ikarus]17
Trojan Horse [Symantec]17
Trojan-Spy.Win32.Banker.RM [Ikarus]17
Virus.Win32.Virut.q [Ikarus]17
W32.Virut [Ikarus]17
Email-Worm.Win32.Mydoom.bj [Ikarus]16
PE_VIRUX.F-3 [Trend Micro]16
Trojan.Agent.DEL [PC Tools]16
W32.Mytob@mm [Symantec]16
Packed.Win32.Koblu [Ikarus]15
PE_VIRUX.F-2 [Trend Micro]15
Exploit.Win32.IMG-WMF [Ikarus]14
Backdoor.Win32.Beastdoor [Ikarus]13
Backdoor.Win32.Bifrose [Ikarus]13
Mal/FakeVirPk-A, W32/Scribble-B [Sophos]13
New Win32.g2 [McAfee]12
Spammer [Ikarus]11
Trojan-Downloader.Win32.Banload [Ikarus]11
VirTool.Win32.DelfInject [Ikarus]11
Trojan-Dropper.Agent [Ikarus]10
BackDoor-CEP.gen.g [McAfee]9
Mal/Bifrose-S, Mal/Bifrose-S, W32/Scribble-B [Sophos]9
PWS-Banker [McAfee]9
Spam-Mailbot.h.gen.a [McAfee]9
Virus.Win32.Virtob [Ikarus]9
Win-Trojan/Midgare.32256 [AhnLab]9
Backdoor.Win32.Refpron [Ikarus]8
BackDoor-CEP.svr [McAfee]8
BKDR_BIFROSE.MIC [Trend Micro]8
New Win32.g3 [McAfee]8
PE_VIRUX.D-1 [Trend Micro]8
PE_VIRUX.E-4 [Trend Micro]8
PE_VIRUX.J-4 [Trend Micro]8
Spy-Agent.bv.gen.b [McAfee]8
Trojan.Win32.Agent.bcn [Kaspersky Lab]8
Trojan.Win32.Patched [Ikarus]8
Trojan.Win32.VB [Ikarus]8
Trojan-Clicker.Win32.Delf [Ikarus]8
W32.SillyFDC [Symantec]8
Backdoor.Bifrose.AHY [PC Tools]7
BKDR_AHZE.NY [Trend Micro]7
Downloader [Symantec]7
Mal/Behav-043, W32/Scribble-B [Sophos]7
Mal/HckPk-A [Sophos]7
Packed.Win32.Katusha.c [Kaspersky Lab]7
Packed.Win32.Krap.b [Kaspersky Lab]7
Trojan.Midgare.hhn [PC Tools]7
Trojan-Downloader.Win32.Small [Ikarus]7
Virus.Trojan.Win32.Midgare [Ikarus]7
Win32.Cadoiac.A [Ikarus]7
Backdoor.Win32.Small.uc [Kaspersky Lab]6
Generic PWS.ak [McAfee]6
Trojan.Adclicker [Symantec]6
Trojan-Clicker.Win32.VB [Ikarus]6
Trojan-Dropper [Ikarus]6
Trojan-Spy.Win32.VB [Ikarus]6
Virus.W32.Sality [Ikarus]6
Virus.Win32.Virut.n [Ikarus]6
Win32.Virtob.2 [Ikarus]6
Win-Trojan/Bifrose.29053 [AhnLab]6
Win-Trojan/Xema.variant [AhnLab]6
Backdoor.Win32.Agent.adql [Kaspersky Lab]5
Backdoor.Win32.Bifrose.fpb [Kaspersky Lab]5
Cutwail [McAfee]5

Virus:Win32/Virut.BM [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
China329
Russian Federation101
Sweden94
Germany57
Spain39
United Kingdom37
Brazil20
Saudi Arabia17
Taiwan15
France12
Italy12
Turkey10
Poland9
Portugal7
Australia6
Belgium6
Israel6
Czech Republic5
Netherlands4
Egypt3
Austria2
Canada2
Greece2
Iran2
Japan2
Jordan2
Norway2
Chile1
Denmark1
Finland1
Indonesia1
Iraq1
Lebanon1
Oman1
Republic of Korea1
Romania1
Slovakia1
Slovenia1
Syria1

Virus:Win32/Virut.BM [Microsoft] is known to be created as:
%AppData%\csrss.exe
%AppData%\microsoft\windows\lsass.exe
%CommonPrograms%\startup\startup.exe
%FontsDir%\fonts.exe
%FontsDir%\logcde.dll
%FontsDir%\services.exe
%FontsDir%\svchost.exe
%FontsDir%\tskmgr.exe
%FontsDir%\unwise_.exe
%FontsDir%\windef.dll
%LocalSettings%\carbon.exe
%LocalSettings%\tempkey.exe
%ProgramFiles%\alphaant\alpha.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\sosue.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\gamazer.3.exe
%ProgramFiles%\manson\liser.exe
%ProgramFiles%\meex.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\no-ip\duc20.exe
%ProgramFiles%\thunmail\testabd.exe
%ProgramFiles%\windows\csrss.exe
%System%\.00cd1a40\00cd1a40.exe
%System%\1054v.exe
%System%\1061044.exe
%System%\1114878.exe
%System%\1124216.exe
%System%\1392618.exe
%System%\1472391.exe
%System%\1502472.exe
%System%\1587167.exe
%System%\1673281.exe
%System%\1772553.exe
%System%\1775869.exe
%System%\1949257.exe
%System%\2501627.exe
%System%\2713724.exe
%System%\28463\svchost.exe
%System%\2851786.exe
%System%\28892.exe
%System%\294748.exe
%System%\3361\svchost.exe
%System%\3429789.exe
%System%\3555246.exe
%System%\3780283.exe
%System%\3827158.exe
%System%\3833211.exe
%System%\3967233.exe
%System%\4121012.exe
%System%\4337687.exe
%System%\4348703.exe
%System%\4350657.exe
%System%\4358164.exe
%System%\4548869.exe
%System%\4662394.exe
%System%\467663.exe
%System%\5220132.exe
%System%\5510813.exe
%System%\5556131.exe
%System%\5621714.exe
%System%\5781036.exe
%System%\5919718.exe
%System%\5922922.exe
%System%\5934549.exe
%System%\5941568.exe
%System%\6383005.exe
%System%\6424219.exe
%System%\6568857.exe
%System%\6603799.exe
%System%\8010345.exe
%System%\8062185.exe
%System%\8076701.exe
%System%\8293861.exe
%System%\8502908.exe
%System%\8661598.exe
%System%\8938547.exe
%System%\9474588.exe
%System%\9480844.exe
%System%\9749246.exe
%System%\adodca.exe
%System%\amvo.exe
%System%\ansid.exe
%System%\bifrost\server.exe
%System%\blphc35dj0erc1.scr
%System%\bndmss.exe
%System%\bttnserv.exe
%System%\ckvo.exe
%System%\cmd.com
%System%\dllcache\default.exe
%System%\dllcache\global.exe
%System%\dllcache\regedit32.com
%System%\dllcache\rndll32.exe
%System%\dllcache\shell32.com
%System%\dllcache\svchost.exe
%System%\dllcache\tskmgr.exe
%System%\dllcache\zipexr.dll
%System%\dllchache.exe
%System%\drivers\drivers.cab.exe
%System%\dxdiag.com
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).