Threat Search: 

ThreatExpert's Statistics for W32/Virut.n.gen [McAfee]:

W32/Virut.n.gen [McAfee] is also known as:
Threat AliasNumber of Incidents
W32.Virut.CF [Symantec]1,901
W32/Scribble-B [Sophos]1,883
Virus.Win32.Virut.ce [Kaspersky Lab]1,858
Virus:Win32/Virut.BM [Microsoft]1,612
Win32/Virut.F [AhnLab]1,407
Win32/Virut.E [AhnLab]516
Malware.Virut [PC Tools]422
Virus:Win32/Virut.gen!O [Microsoft]248
PE_VIRUX.H-3 [Trend Micro]115
Virus.Win32.Virut [Ikarus]78
PE_VIRUX.E-2 [Trend Micro]49
Virus.Win32.Bifrose [Ikarus]46
Virus.Win32.Sality [Ikarus]43
Mal/Bifrose-S, W32/Scribble-B [Sophos]32
Trojan-Downloader.Win32.Agent.czsd [Kaspersky Lab]32
PE_VIRUX.E-3 [Trend Micro]25
Trojan-Banker.Win32.Bancos [Ikarus]25
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]23
Backdoor.Win32.Small.uc [Kaspersky Lab]20
Virus.Virut.j [PC Tools]20
Virus.Win32.Virut.bo [Ikarus]20
PE_VIRUX.A-1 [Trend Micro]19
PE_VIRUX.F-3 [Trend Micro]18
PE_VIRUX.F-2 [Trend Micro]15
Mal/Scribble-C, W32/Scribble-B [Sophos]13
Packed.Win32.Koblu [Ikarus]13
Backdoor.Win32.Bifrose [Ikarus]11
Trojan-Downloader.Win32.Banload [Ikarus]11
Trojan-Spy.Win32.Banker.RM [Ikarus]11
Virus.Win32.JunkPoly [Ikarus]11
W32.Virut [Ikarus]11
Trojan.Win32.Agent2.hxw [Kaspersky Lab]10
TrojanProxy:Win32/Slenugga.A [Microsoft]10
Trojan.Win32.Banker [Ikarus]9
Trojan-Clicker.Win32.VB [Ikarus]9
Trojan-Downloader.Win32.Small [Ikarus]9
PE_VIRUX.E-4 [Trend Micro]8
PE_VIRUX.J-4 [Trend Micro]8
Trojan-Clicker.Win32.Delf [Ikarus]8
Trojan-Spy.Win32.VB [Ikarus]8
PE_VIRUX.A [Trend Micro]7
Virus.Win32.Virut.q [Ikarus]7
W32/DelpBck-Gen [Sophos]7
Mal/Behav-043, W32/Scribble-B [Sophos]6
Trojan-Downloader.Win32.Cutwail [Ikarus]6
VirTool.Win32.DelfInject [Ikarus]6
Virus:Win32/Virut.gen!N [Microsoft]6
W32.SillyFDC [Symantec]6
Backdoor.Win32.Beastdoor [Ikarus]5
Backdoor.Win32.Small.uh [Kaspersky Lab]5
Mal/EncPk-FS, W32/Scribble-B [Sophos]5
Mal/FakeVirPk-A, W32/Scribble-B [Sophos]5
Packed.Win32.Krap.b [Kaspersky Lab]5
Trojan.Generic [Ikarus]5
Trojan.Win32.Patched [Ikarus]5
Trojan-Clicker.VB.cwf [PC Tools]5
Trojan-Downloader.LoadAdv [Ikarus]5
Trojan-Dropper.Agent [Ikarus]5
Trojan-Spy.Win32.Banker [Ikarus]5
Win32.Cadoiac.A [Ikarus]5
Win32/ReaBot.worm.60929 [AhnLab]5
Win-Trojan/Xema.variant [AhnLab]5
Worm.Win32.AutoRun [Ikarus]5
Backdoor.Rustock [Ikarus]4
Backdoor.Win32.PoisonIvy.az [Ikarus]4
Gen.Malware [Ikarus]4
Mal/Behav-103, Mal/Behav-043, W32/Scribble-B [Sophos]4
P2P-Worm.Win32.Palevo [Ikarus]4
PE_VIRUX.J-3 [Trend Micro]4
Trojan.Pandex [PC Tools]4
Trojan.Pandex [Symantec]4
Trojan-Downloader.Win32.Agent.czmx [Kaspersky Lab]4
Trojan-Downloader.Win32.Suurch [Ikarus]4
Trojan-Downloader.Win32.Zlob [Ikarus]4
Trojan-Dropper.Win32.ExeBind [Ikarus]4
Trojan-Dropper.Win32.ExeBind [Kaspersky Lab]4
TrojanDropper:Win32/ExeBind [Microsoft]4
Trojan-PWS.Win32.LdPinch [Ikarus]4
Virus.Virut.ce [PC Tools]4
Virus.Win32.Virtob [Ikarus]4
Virus:Win32/Chir.B@mm [Microsoft]4
Backdoor.Refpron [Ikarus]3
Backdoor.Sdbot [Symantec]3
Backdoor.Win32.Small.ibb [Kaspersky Lab]3
Backdoor.Win32.VB [Ikarus]3
Downloader.Trojan [Symantec]3
Mal/EncPk-BH, W32/Scribble-B [Sophos]3
Mal/EncPk-JB, W32/Scribble-B [Sophos]3
Mal/Generic-A, W32/Scribble-B [Sophos]3
PE_VIRUX.D-1 [Trend Micro]3
Spammer [Ikarus]3
Trojan Horse [Symantec]3
Trojan.Midgare.EYZ [PC Tools]3
Trojan.Win32.Agent.bcn [Kaspersky Lab]3
Trojan.Win32.Anomaly [Ikarus]3
Trojan.Win32.Malagent [Ikarus]3
Trojan.Win32.ProcessHijack [Ikarus]3
Trojan-Banker.Win32.Banker [Ikarus]3
TrojanDownloader:Win32/Cutwail.AQ [Microsoft]3
VirTool.Win32.VBInject [Ikarus]3

W32/Virut.n.gen [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China200
Russian Federation84
Sweden57
Germany37
Spain25
United Kingdom20
Brazil13
Saudi Arabia13
Taiwan11
France10
Italy9
Turkey8
Israel5
Australia4
Poland4
Czech Republic3
Iran3
Netherlands3
Portugal3
Iraq2
Jordan2
Austria1
Belgium1
Chile1
Egypt1
Hungary1
Lebanon1
Oman1
Republic of Korea1
Slovakia1
Syria1

W32/Virut.n.gen [McAfee] is known to be created as:
%AppData%\csrss.exe
%AppData%\sysdate32.exe
%CommonPrograms%\chkdisk.exe
%CommonPrograms%\startup\startup.exe
%FontsDir%\fonts.exe
%FontsDir%\logcde.dll
%FontsDir%\services.exe
%FontsDir%\svchost.exe
%FontsDir%\tskmgr.exe
%FontsDir%\uninstall_.exe
%FontsDir%\unwise_.exe
%FontsDir%\windef.dll
%LocalSettings%\carbon.exe
%LocalSettings%\tempkey.exe
%ProgramFiles%\alphaant\alpha.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\gamazer.3.exe
%ProgramFiles%\manson\liser.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\microsoft office\winword.exe
%ProgramFiles%\mirc\irc bot\services.exe
%ProgramFiles%\movie maker\svchost.exe
%ProgramFiles%\no-ip\duc20.exe
%ProgramFiles%\thunmail\testabd.exe
%ProgramFiles%\windows\csrss.exe
%System%\1054v.exe
%System%\1061044.exe
%System%\1114878.exe
%System%\1124216.exe
%System%\1392618.exe
%System%\1472391.exe
%System%\1502472.exe
%System%\155309.exe
%System%\1587167.exe
%System%\1673281.exe
%System%\1772553.exe
%System%\1775869.exe
%System%\1949257.exe
%System%\2501627.exe
%System%\2713724.exe
%System%\28463\svchost.exe
%System%\2851786.exe
%System%\28892.exe
%System%\294748.exe
%System%\3361\svchost.exe
%System%\3429789.exe
%System%\3555246.exe
%System%\3780283.exe
%System%\3827158.exe
%System%\3833211.exe
%System%\3967233.exe
%System%\4121012.exe
%System%\4337687.exe
%System%\4348703.exe
%System%\4350657.exe
%System%\4358164.exe
%System%\4548869.exe
%System%\4662394.exe
%System%\467663.exe
%System%\5220132.exe
%System%\5510813.exe
%System%\5556131.exe
%System%\5621714.exe
%System%\5781036.exe
%System%\5919718.exe
%System%\5922922.exe
%System%\5934549.exe
%System%\5941568.exe
%System%\6180215.exe
%System%\6383005.exe
%System%\6424219.exe
%System%\6568857.exe
%System%\6603799.exe
%System%\6953501.exe
%System%\7607646.exe
%System%\8010345.exe
%System%\8062185.exe
%System%\8076701.exe
%System%\8149465.exe
%System%\8293861.exe
%System%\8502908.exe
%System%\8661598.exe
%System%\8934225.exe
%System%\8938547.exe
%System%\9189962.exe
%System%\9305519.exe
%System%\9474588.exe
%System%\9480844.exe
%System%\9749246.exe
%System%\9763712.exe
%System%\adodca.exe
%System%\ansid.exe
%System%\ashevtsvc.exe
%System%\av_md.exe
%System%\bndmss.exe
%System%\csrsc.exe
%System%\dllcache\default.exe
%System%\dllcache\global.exe
%System%\dllcache\regedit32.com
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).