Threat Search: 

ThreatExpert's Statistics for W32/Scribble-A [Sophos]:

W32/Scribble-A [Sophos] is also known as:
Threat AliasNumber of Incidents
Virus:Win32/Virut.BM [Microsoft]297
W32.Virut.CF [Symantec]293
Virus.Win32.Virut.ce [Kaspersky Lab]269
W32/Virut.n [McAfee]148
New Win32 [McAfee]69
New Win32.g4 [McAfee]24
PE_VIRUX.A [Trend Micro]16
PE_VIRUX.A-1 [Trend Micro]15
Win32/Virut.F [AhnLab]13
Virus.Win32.Virut.q [Ikarus]11
Win32/Virut.E [AhnLab]9
Email-Worm.Win32.Mydoom.bj [Ikarus]8
Trojan.Agent.DEL [PC Tools]8
W32.Mytob@mm [Symantec]8
New Poly Win32 [McAfee]7
Virus.Win32.Sality [Ikarus]6
Win32.Virtob.2 [Ikarus]6
New Win32.g2 [McAfee]5
Backdoor.Win32.Agent.adql [Kaspersky Lab]4
New Malware.js [McAfee]4
Trojan.Adclicker [Symantec]4
Virus.Win32.Virut.ak [Ikarus]4
Virus.Win32.Virut.bo [Ikarus]4
Backdoor.Win32.Frauder [Ikarus]3
New Malware.bj [McAfee]3
PE_VIRUX.D-1 [Trend Micro]3
Spammer:Win32/Tedroo.I [Microsoft]3
Trojan.Win32.Patched [Ikarus]3
Trojan.Win32.Piptea [Ikarus]3
Virus.Win32.Virtob [Ikarus]3
Virus.Win32.Virut [Ikarus]3
Backdoor.Win32.Beastdoor [Ikarus]2
Backdoor.Win32.Popwin [Ikarus]2
Email-Worm.Win32.Tanatos.B [Ikarus]2
Exploit.Win32.IMG-WMF [Ikarus]2
Packed.Win32.Koblu [Ikarus]2
Trojan Horse [Symantec]2
Trojan.Spammer [Ikarus]2
Trojan-Spy.Win32.Banker.RM [Ikarus]2
Virus.Win32.Virut.n [Ikarus]2
Virus:Win32/Virut.gen!G [Microsoft]2
W32.Virut [Ikarus]2
Win32.Cadoiac.A [Ikarus]2
Worm.Win32.Neeris [Ikarus]2
Worm:Win32/Neeris.AN [Microsoft]2
Backdoor.Win32.IRCBot [Ikarus]1
Backdoor.Win32.PoisonIvy [Ikarus]1
Backdoor:Win32/Refpron.M [Microsoft]1
BehavesLikeWin32.ProcessHijack [Ikarus]1
Email-Worm.Win32.VB.cb [Ikarus]1
Generic Dropper.cx [McAfee]1
IM-Worm.Win32.VB [Ikarus]1
Mal_Banker [Trend Micro]1
New Malware.bx [McAfee]1
not-a-virus:AdWare.Win32.MyWebSearch [Ikarus]1
not-a-virus:Server-FTP.Win32.Serv-U.50011 [Ikarus]1
P2P-Worm.Win32.Agent [Ikarus]1
Spam-Mailbot [McAfee]1
Spam-Mailbot.c [McAfee]1
Spam-Mailbot.gen.a [McAfee]1
Spam-Mailbot.h.gen.a [McAfee]1
Spammer [Ikarus]1
Suspicious.MH690 [Symantec]1
Trojan.Fakealert.AAI [Ikarus]1
Trojan.Win32.Refpron [Ikarus]1
Trojan.Win32.VB [Ikarus]1
Trojan.Zlob [Ikarus]1
Trojan:Win32/Malagent [Microsoft]1
Trojan-Downloader.Harnig.ZC [Ikarus]1
Trojan-Downloader.Win32.Agent.bjzh [Kaspersky Lab]1
TrojanDownloader:Win32/Cutwail.gen!C [Microsoft]1
TrojanDownloader:Win32/Donise.B [Microsoft]1
Trojan-Dropper.Delf [Ikarus]1
Trojan-Dropper.Win32.Cutwail [Ikarus]1
Trojan-PWS.Win32.Delf [Ikarus]1
Trojan-Spy.Win32.ProAgent.21 [Ikarus]1
VirTool.Win32.Vbinder [Ikarus]1
Virus.Win32.Agent.cb [Kaspersky Lab]1
Virus.Win32.Godog [Ikarus]1
Virus.Win32.Hupigon.MAP [Ikarus]1
Virus.Win32.Socks.BA [Ikarus]1
Virus.Win32.Virut.av [Ikarus]1
Virus:Win32/Smee.A [Microsoft]1
Virus:Win32/Virut.gen!E [Microsoft]1
Virus:Win32/Virut.gen!F [Microsoft]1
W32.Fidameg.A [Symantec]1
W32.Imaut [Symantec]1
W32.Spybot.Worm [Symantec]1
W32/Caveduck.a [McAfee]1
W32/Virut.n!inf [McAfee]1
Win32.Virtob.P [Ikarus]1
Win32.Virut.Gen.4 [PC Tools]1
Worm.Win32.AutoRun.aayn [Kaspersky Lab]1

W32/Scribble-A [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
China30
Germany6
Spain4
United Kingdom4
Brazil3
France3
Taiwan3
Italy2
Russian Federation2
Canada1
Czech Republic1
Greece1
Netherlands1
Norway1
Sweden1
Turkey1

W32/Scribble-A [Sophos] is known to be created as:
%System%\blphc35dj0erc1.scr
%System%\bootinit.exe
%System%\bttnserv.exe
%System%\cmd.com
%System%\csrsc.exe
%System%\dxdiag.com
%System%\flash.10.exe
%System%\grcrt.exe
%System%\grcrt2.exe
%System%\jambanmu.com
%System%\keygen.exe
%System%\load.exe
%System%\lphc35dj0erc1.exe
%System%\msconfig.com
%System%\msrstart.exe
%System%\netvdm.exe
%System%\nxtepad.exe
%System%\olhrwef.exe
%System%\patch.exe
%System%\ping.com
%System%\reader_s.exe
%System%\readme.exe
%System%\regedit.com
%System%\rvhost.exe
%System%\safetray.exe
%System%\setup.exe
%System%\system.exe
%System%\vamsoft.exe
%System%\winsit.exe
%Temp%\acch8gh5fscyv.exe
%Temp%\csrssc.exe
%Temp%\d3tidso8f53.exe
%Temp%\glb1a2b.exe
%Temp%\h13wr98.exe
%Temp%\li7tsg6m73q1.exe
%Temp%\p0kcvm5yqb.exe
%Temp%\p5wcslh.exe
%Temp%\tkdazkdfuhoon.exe
%Temp%\zcilitfgwv.exe
%Temp%\zsyxaf6zsz.exe
%UserProfile%\keygen.exe
%UserProfile%\reader_s.exe
%UserProfile%\readme.exe
%Windir%\9129837.exe
%Windir%\dc.exe
%Windir%\help\other.exe
%Windir%\inf\other.exe
%Windir%\rvhost.exe
%Windir%\services.exe
%Windir%\svchost.exe
%Windir%\sviq.exe
%Windir%\sysguard.exe
%Windir%\system\fun.exe
c:\extracted\lover.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.