Threat Search: 

ThreatExpert's Statistics for Virus:Win32/Virut.L [Microsoft]:

Virus:Win32/Virut.L [Microsoft] is also known as:
Threat AliasNumber of Incidents
Virus.Win32.Virut.q [Kaspersky Lab]106
W32.Virut.U [Symantec]104
PE_VIRUT.XO [Trend Micro]103
W32/Virut.gen [McAfee]98
Win32.Virut.Gen.5 [PC Tools]95
W32/Vetor-A [Sophos]94
Win32/Virut.D [AhnLab]54
Virus.Win32.Virut [Ikarus]32
Virus.Win32.Sality [Ikarus]18
Trojan-Downloader.Win32.VB.bbi [Ikarus]10
Mal/EncPk-BW, W32/Vetor-A [Sophos]5
PWS-Banker.gen.aa [McAfee]4
Spam-Mailbot [McAfee]4
Email-Worm.Win32.Runouce.b [Kaspersky Lab]3
Mal/Behav-164, W32/Vetor-A [Sophos]3
PE_Chir.B [Trend Micro]3
W32.SillyFDC [Symantec]3
W32/Chir.b@MM [McAfee]3
W32/Chir-B [Sophos]3
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]2
W32.Rajump [Symantec]2
Win32/ChiHack.6652 [AhnLab]2
Win32/Virut.C [AhnLab]2
Win-Trojan/Downloader.11264.GK [AhnLab]2
Win-Trojan/Downloader.8704.XA [AhnLab]2
Win-Trojan/Xema.variant [AhnLab]2
Backdoor.Win32.IRCBot [Ikarus]1
Backdoor.Win32.mIRC-based.k [Ikarus]1
Backdoor.Wootbot.YZ [PC Tools]1
Email-Worm.Win32.Generic [Ikarus]1
Email-Worm.Win32.Joleee.bed [Kaspersky Lab]1
FakeAlert-AG.gen.c [McAfee]1
JS.Chir.B [PC Tools]1
Mal/Dorf-E, W32/Vetor-A [Sophos]1
Mal/Generic-A [Sophos]1
Mal/HckPk-A [Sophos]1
Mal/Pushdo-A, W32/Vetor-A [Sophos]1
Mal/TibsPak, W32/Vetor-A [Sophos]1
Mal_MLWR-5 [Trend Micro]1
Net-Worm.Win32.Allaple.a [Ikarus]1
P2P-Worm.Win32.SpyBot.gl [Ikarus]1
PE_MADANGEL.D [Trend Micro]1
TROJ_NUWAR.DDJ [Trend Micro]1
Trojan.Agent.VYJ [PC Tools]1
Trojan.DL.AutoIt.DO [PC Tools]1
Trojan.FakeAV [Symantec]1
Trojan.Inject [Ikarus]1
Trojan.Win32.Pakes.cob [Kaspersky Lab]1
Trojan-Dropper.Kobcka [Ikarus]1
Trojan-Dropper.Win32.Autoit [Ikarus]1
Trojan-Spy.Ardamax.J [Ikarus]1
TrojanSpy.Ardamax.WQ [PC Tools]1
Virus.Win32.Hupigon.MAP [Ikarus]1
Virus.Win32.PurityScan.AF [Ikarus]1
Virus.Win32.Small [Ikarus]1
Virus.Win32.Small.l [Kaspersky Lab]1
Virus.Win32.VB.bg [Ikarus]1
Virus.Win32.Virut.bt [Ikarus]1
Virus.Win32.Virut.q [Ikarus]1
Virus.Worm.Win32.AutoRun.doq [Ikarus]1
W32.Chir.B@mm [Symantec]1
W32.Madangel [Symantec]1
W32.Svich [Symantec]1
W32/Dref-AW [Sophos]1
W32/Madangel.b [McAfee]1
W32/Madang-Fam [Sophos]1
Win32.Cadoiac.A [Ikarus]1
Win32.Virtob.2 [Ikarus]1
Win-Trojan/Agent.11264.JZ [AhnLab]1
Win-Trojan/Agent.36352.GC [AhnLab]1
Win-Trojan/Agent.9216.FL [AhnLab]1
Win-Trojan/Mirc-based.705312 [AhnLab]1
Win-Trojan/Spambot.7680 [AhnLab]1
Worm.AutoIT.V [PC Tools]1
Worm.IRCBot.GP [PC Tools]1
Worm.VB.FMU [PC Tools]1

Virus:Win32/Virut.L [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Brazil9
China5
United Kingdom4
Russian Federation2
France1
Germany1
Israel1
Republic of Korea1
Romania1
Taiwan1
Turkey1

Virus:Win32/Virut.L [Microsoft] is known to be created as:
%AllUsersProfile%\desktop.exe
%AllUsersProfile%\favorites.exe
%AppData%\microsoft\cd burning\khatra.exe
%CommonDesktopDir%\desktop.exe
%CommonFavorites%\favorites.exe
%DesktopDir%\desktop.exe
%FontsDir%\services.exe
%FontsDir%\unwise_.exe
%ProgramFiles%\microsoft office\winword.exe
%ProgramFiles%\mirc\irc bot\services.exe
%ProgramFiles%\twain\twain.exe
%System%\3361\svchost.exe
%System%\6292775.exe
%System%\793693.exe
%System%\algi.exe
%System%\dllcache\regedit32.com
%System%\dllcache\shell32.com
%System%\dllchache.exe
%System%\exlorers.exe
%System%\fastnetsrv.exe
%System%\khatra.exe
%System%\m5vbvm60.exe
%System%\msmsgs.exe
%System%\msnmanegers.exe
%System%\opeia.exe
%System%\reader_s.exe
%System%\rpcsvc.exe
%System%\rund1132.exe
%System%\servises.exe
%System%\ssvichosst.exe
%System%\wmdtc.exe
%System%\wuauc1t.exe
%System%\ylupkt.exe
%Temp%\alg.exe
%Temp%\alh.exe
%UserProfile%\desktop.exe
%UserProfile%\reader_s.exe
%Windir%\bashwin32.exe
%Windir%\dhcp\svchost.exe
%Windir%\khatarnakh.exe
%Windir%\msa.exe
%Windir%\neos.exe
%Windir%\services.exe
%Windir%\ssvichosst.exe
%Windir%\svchost.exe
%Windir%\system\ghost.exe
%Windir%\system32.exe
%Windir%\xplorer.exe
c:\explorer.exe
c:\khatra.exe
c:\ravmon.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.