Threat Search: 

ThreatExpert's Statistics for Virus.Win32.Virut.n [Ikarus]:

Virus.Win32.Virut.n [Ikarus] is also known as:
Threat AliasNumber of Incidents
Generic Packed [McAfee]32,955
Troj/Agent-HAP [Sophos]31,434
Trojan-Downloader.NUS [PC Tools]28,223
Win-Trojan/Tinytro.705 [AhnLab]14,198
Trojan.Win32.Agent2.hoc [Kaspersky Lab]4,735
Trojan.Tiny.bem [PC Tools]169
Virus.Win32.Virut.n [Kaspersky Lab]119
W32.Rahack.W [Symantec]73
W32/Allaple-F [Sophos]73
W32/RAHack [McAfee]73
Worm.Allaple.Gen [PC Tools]73
Worm:Win32/Allaple.A [Microsoft]73
WORM_ALLAPLE.IK [Trend Micro]73
W32/Virut.gen [McAfee]42
Win32.Virut.Gen [PC Tools]31
Win32.Virut.Gen.4 [PC Tools]29
Virus:Win32/Virut.AK [Microsoft]26
W32.Virut.B [Symantec]25
W32/Vetor-A [Sophos]24
W32/Virut-T [Sophos]22
W32.Virut.A [Symantec]21
PE_VIRUT.A [Trend Micro]19
PE_VIRUT.D [Trend Micro]19
W32/Virut.a [McAfee]19
Adware.CDN [PC Tools]18
Adware-BDSearch [McAfee]18
Virus.Win32.Virut.a [Kaspersky Lab]16
Virus:Win32/Virut.A [Microsoft]16
W32/Virut.gen.a [McAfee]14
W32/Virut-L [Sophos]14
Generic Malware.eb [McAfee]12
Virus:Win32/Virut.D [Microsoft]12
W32.Virut.CF [Symantec]12
W32.Virut.W [Symantec]12
W32.Virut.H [Symantec]11
W32/Scribble-B [Sophos]9
PE_VIRUT.AV [Trend Micro]8
Virus.Win32.Virut.ce [Kaspersky Lab]8
Virus:Win32/Virut.AC [Microsoft]8
W32.Spybot.Worm [Symantec]8
W32/Virut-W [Sophos]8
Backdoor.Win32.VanBot.ax [Kaspersky Lab]7
Trojan Horse [Symantec]7
Virus.Win32.Virut.av [Kaspersky Lab]7
W32/Virut-Gen [Sophos]7
Backdoor:Win32/Poebot.gen [Microsoft]6
Mal/EncPk-AO [Sophos]6
PE_VIRUT.AT [Trend Micro]6
Virus.Win32.Virut.at [Kaspersky Lab]6
Virus:Win32/Virut.BM [Microsoft]6
Win32/Virut.B [AhnLab]6
Win32/Virut.F [AhnLab]6
Mal/Generic-A [Sophos]5
Virus:Win32/Virut.AA [Microsoft]5
Win32/IRCBot.worm.variant [AhnLab]5
Win32/Virut.D [AhnLab]5
Backdoor:Win32/Poebot.BG [Microsoft]4
Mal/Behav-249 [Sophos]4
Trojan.Win32.KillFiles.aee [Kaspersky Lab]4
TrojanSpy:Win32/Bancos.gen!C [Microsoft]4
Virus:Win32/Virut.gen!O [Microsoft]4
W32.Virut.R [Symantec]4
Backdoor.VanBot.CL [PC Tools]3
Generic.dx [McAfee]3
Mal/Packer [Sophos]3
New Malware.eb [McAfee]3
New Win32 [McAfee]3
PE_VIRUT.B [Trend Micro]3
PE_VIRUT.XP [Trend Micro]3
Virus.Win32.Virut.b [Kaspersky Lab]3
Virus.Win32.Virut.q [Kaspersky Lab]3
W32.IRCBot [Symantec]3
W32.IRCBot.Gen [Symantec]3
W32.Virut.U [Symantec]3
W32/Virut.b [McAfee]3
W32/Virut.n.gen [McAfee]3
Win32.Virut.Gen.5 [PC Tools]3
Win32/MalPackedB.suspicious [AhnLab]3
Win32/Virut.C [AhnLab]3
Win32/Virut.E [AhnLab]3
Backdoor.VanBot!sd5 [PC Tools]2
Downloader [Symantec]2
Generic PUP.x [McAfee]2
Mal/Behav-164, Mal/Dorf-D, Mal/TibsPak [Sophos]2
Net-Worm.Win32.Kolabc.btq [Kaspersky Lab]2
New Win32.g3 [McAfee]2
not-a-virus:Monitor.Win32.ActMon.511 [Kaspersky Lab]2
PE_VIRUT.XK [Trend Micro]2
Suspicious.MH690 [Symantec]2
Trojan.KillFiles!sd6 [PC Tools]2
Trojan:Win32/Autorun.I [Microsoft]2
Virus.Virut!ct [PC Tools]2
Virus.Virut.na [PC Tools]2
Virus:Win32/Sality.AM [Microsoft]2
Virus:Win32/Virut.AE [Microsoft]2
Virus:Win32/Virut.AN [Microsoft]2
Virus:Win32/Virut.B [Microsoft]2
W32.Sality.AE [Symantec]2
W32.SillyFDC [Symantec]2
W32/Scribble-A [Sophos]2

Virus.Win32.Virut.n [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation2,536
China172
Brazil7
Germany2
Netherlands1
Poland1
Spain1
United Kingdom1

Virus.Win32.Virut.n [Ikarus] is known to be created as:
%AppData%\dxdlls\dxdlg.exe
%CommonPrograms%\startup\avg.exe
%FontsDir%\services.exe
%ProgramFiles%\common files\system\ado\tsektjkj.exe
%ProgramFiles%\netmeeting\rsewzjqn.exe
%ProgramFiles%\ocins\idnsvr.exe
%System%\algs.exe
%System%\csrs.exe
%System%\cuarentena de kingsoft\knawaduh.exe
%System%\cuarentena de kingsoft\pehbb.exe
%System%\dxdlg.exe
%System%\explorer.exe
%System%\firewall.exe
%System%\frmwrk32.exe
%System%\iexplore.exe
%System%\iexplorer.exe
%System%\isass.exe
%System%\logon.exe
%System%\lssas.exe
%System%\ntos.exe
%System%\plms.exe
%System%\spooisv.exe
%System%\spoolsvc.exe
%System%\system.exe
%System%\urdvxc.exe
%System%\winamp.exe
%System%\winiogon.exe
%System%\winupdate.exe
%System%\wmplayer12.exe
%System%\wproxp.exe
%Temp%\06.04.09.exe
%Temp%\1\idnsvr.exe
%Temp%\12\idnsvr.exe
%Temp%\2\idnsvr.exe
%Temp%\2008.exe
%Temp%\2009.exe
%Temp%\3\idnsvr.exe
%Temp%\4\idnsvr.exe
%Temp%\5\idnsvr.exe
%Temp%\a\idnsvr.exe
%Temp%\cuopy.exe
%Temp%\desae.exe
%Temp%\foucplc.exe
%Temp%\june.exe
%Temp%\owpqhu.exe
%Temp%\ter.exe
%Temp%\virus\yjqcq.exe
%Windir%\netsvc.exe
%Windir%\netui.exe
%Windir%\pchealth\helpctr\system\compatctr\hrtbebze.exe
%Windir%\pchealth\helpctr\system\compatctr\jbnxjtkn.exe
%Windir%\pchealth\helpctr\system\compatctr\tnslrrhk.exe
%Windir%\pchealth\helpctr\system\dvdupgrd\shrrtjet.exe
%Windir%\pchealth\helpctr\system\errmsg\vlvxqrek.exe
%Windir%\pchealth\helpctr\system\errors\jcjjlqnq.exe
%Windir%\pchealth\helpctr\system\netdiag\hsjqschn.exe
%Windir%\pchealth\helpctr\system\netdiag\xrvxszvs.exe
%Windir%\pchealth\helpctr\system\panels\nntlskwn.exe
%Windir%\pchealth\helpctr\system\panels\sncncweb.exe
%Windir%\pchealth\helpctr\system\rc\qbrblthb.exe
%Windir%\pchealth\helpctr\system\remote assistance\rqxjhbsl.exe
%Windir%\pchealth\helpctr\system\remote assistance\rzqstbqq.exe
%Windir%\pchealth\helpctr\system\remote assistance\wesnhzec.exe
%Windir%\pchealth\helpctr\system\sysinfo\bjlkjrls.exe
%Windir%\pchealth\helpctr\system\sysinfo\cntbrbzr.exe
%Windir%\pchealth\helpctr\system\sysinfo\jbrhbztz.exe
%Windir%\pchealth\helpctr\system\sysinfo\jrtqcssx.exe
%Windir%\pchealth\helpctr\system\sysinfo\rbcjjwqr.exe
%Windir%\pchealth\helpctr\system\sysinfo\rercrnhh.exe
%Windir%\pchealth\helpctr\system\sysinfo\rnbrkrlv.exe
%Windir%\pchealth\helpctr\system\sysinfo\vkchbbxh.exe
%Windir%\pchealth\helpctr\system\updatectr\lwklbvze.exe
%Windir%\pchealth\helpctr\system\updatectr\qxshkkqn.exe
%Windir%\pchealth\helpctr\system\updatectr\rrbvcsbb.exe
%Windir%\pchealth\helpctr\system\updatectr\snqesjrk.exe
%Windir%\pchealth\helpctr\system\updatectr\trkhkjxz.exe
%Windir%\svchost.exe
%Windir%\system\msddll.exe
%Windir%\userinit.exe
%Windir%\web\wcxnjhhj.exe
%Windir%\windows.exe
c:\inetpub\wwwroot\kkvwbsrw.exe
c:\mobimb.exe
c:\tvsknrse.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.