Threat Search: 

ThreatExpert's Statistics for W32/Virut.n [McAfee]:

W32/Virut.n [McAfee] is also known as:
Threat AliasNumber of Incidents
Virus:Win32/Virut.BM [Microsoft]311
W32.Virut.CF [Symantec]304
Virus.Win32.Virut.ce [Kaspersky Lab]285
W32/Scribble-A [Sophos]148
W32/Scribble-B [Sophos]133
Win32/Virut.F [AhnLab]116
Win32/Virut.E [AhnLab]36
PE_VIRUX.A [Trend Micro]23
Mal/HckPk-A, W32/Scribble-B [Sophos]22
PE_VIRUX.A-1 [Trend Micro]19
Virus.Win32.Sality [Ikarus]17
Virus.Win32.Virut.q [Ikarus]8
Email-Worm.Win32.Mydoom.bj [Ikarus]7
Mal/FakeVirPk-A, W32/Scribble-B [Sophos]7
Trojan.Agent.DEL [PC Tools]7
Virus.Win32.Virut.bo [Ikarus]7
W32.Mytob@mm [Symantec]7
Packed.Win32.Katusha.c [Kaspersky Lab]6
Trojan-Spy.Win32.Banker.RM [Ikarus]6
Backdoor.Win32.Popwin [Ikarus]4
Mal/FakeVirPk-A [Sophos]4
Trojan.Adclicker [Symantec]4
Virus.Win32.Virut [Ikarus]4
Win32/IRCBot.worm.Gen [AhnLab]4
Win-Trojan/Katusha.155648.D [AhnLab]4
Trojan.Win32.Patched [Ikarus]3
Trojan-Banker.Win32.Bancos [Ikarus]3
W32.SillyFDC [Symantec]3
Win32.Virtob.2 [Ikarus]3
Email-Worm.Win32.Tanatos.B [Ikarus]2
Exploit.Win32.IMG-WMF [Ikarus]2
I-Worm.Chir.B [PC Tools]2
Packed.Win32.Koblu [Ikarus]2
Trojan-Dropper.Agent [Ikarus]2
Trojan-Dropper.Win32.Cutwail [Ikarus]2
Virus.Win32.Virtob [Ikarus]2
Virus.Win32.Virut.ak [Ikarus]2
W32.Imaut [Symantec]2
W32.Virut [Ikarus]2
Worm.Win32.Neeris [Ikarus]2
Worm:Win32/Neeris.AN [Microsoft]2
Backdoor.Win32.IRCBot [Ikarus]1
Backdoor.Win32.Refpron [Ikarus]1
BehavesLikeWin32.ProcessHijack [Ikarus]1
Downloader.MisleadApp [Symantec]1
Email-Worm.Win32.Runouce [Ikarus]1
Email-Worm.Win32.VB.cb [Ikarus]1
IM-Worm.Win32.VB [Ikarus]1
Infostealer [Symantec]1
Mal/Behav-043, W32/Scribble-B [Sophos]1
Mal/Generic-A, Mal/IRCBot-B, W32/Scribble-B [Sophos]1
not-a-virus:AdWare.Win32.MyWebSearch [Ikarus]1
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]1
P2P-Worm.Win32.Agent [Ikarus]1
Packed.Win32.Krap [Ikarus]1
Packed.Win32.Krap.b [Kaspersky Lab]1
Packed.Win32.Tdss.c [Kaspersky Lab]1
PE_VIRUX.A-2 [Trend Micro]1
Suspicious.MH690 [Symantec]1
Troj/Mdrop-BZI [Sophos]1
Trojan Horse [Symantec]1
Trojan.Autoit [Ikarus]1
Trojan.DL.AutoIt.DO [PC Tools]1
Trojan.Fakealert.AAI [Ikarus]1
Trojan.Midgare.EYZ [PC Tools]1
Trojan.Slenfbot [Ikarus]1
Trojan.Spammer [Ikarus]1
Trojan.Win32.Fakeinit [Ikarus]1
Trojan.Win32.Pakes.cob [Kaspersky Lab]1
Trojan.Zlob [Ikarus]1
Trojan:Win32/Fakeinit [Microsoft]1
Trojan-Clicker.Win32.VB.cvg [Ikarus]1
Trojan-Downloader.Harnig.ZC [Ikarus]1
Trojan-Downloader.Win32.Cutwail [Ikarus]1
Trojan-Downloader.Win32.Suurch [Ikarus]1
Trojan-Spy.Win32.ProAgent.21 [Ikarus]1
VirTool.Win32.CeeInject [Ikarus]1
VirTool.Win32.DelfInject [Ikarus]1
Virus.Virut.ce [PC Tools]1
Virus.W32.Sality [Ikarus]1
Virus.Win32.Godog [Ikarus]1
Virus.Win32.Hakaglan [Ikarus]1
Virus.Win32.Hupigon.MAP [Ikarus]1
Virus.Win32.VB.bg [Ikarus]1
W32.Imaut.N [Symantec]1
W32.IRCBot [Symantec]1
W32.Sality [Ikarus]1
W32.Spybot.Worm [Symantec]1
W32.Svich [Symantec]1
W32/Sohana-AS [Sophos]1
Win32.Cadoiac.A [Ikarus]1
Win32.Virtob.P [Ikarus]1
Win-Trojan/Blank.34304 [AhnLab]1
Worm.Autoit.DU [PC Tools]1
Worm.AutoRun.eee [PC Tools]1
Worm.VB.FMU [PC Tools]1
Worm:Win32/Kulsibot.A [Microsoft]1
WORM_RONTOKBR.BQ [Trend Micro]1

W32/Virut.n [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China30
United Kingdom10
Russian Federation8
Spain5
Germany4
Brazil2
Italy2
Taiwan2
Belgium1
France1
Netherlands1
Sweden1
Turkey1

W32/Virut.n [McAfee] is known to be created as:
%FontsDir%\fonts.exe
%FontsDir%\tskmgr.exe
%FontsDir%\unwise_.exe
%ProgramFiles%\thunmail\testabd.exe
%System%\3361\svchost.exe
%System%\bifrost\server.exe
%System%\blphc35dj0erc1.scr
%System%\bootinit.exe
%System%\bttnserv.exe
%System%\ckvo.exe
%System%\csrsc.exe
%System%\dllcache\default.exe
%System%\dllcache\global.exe
%System%\dllcache\regedit32.com
%System%\dllcache\rndll32.exe
%System%\dllcache\shell32.com
%System%\dllcache\svchost.exe
%System%\dllcache\tskmgr.exe
%System%\dllcache\userinit.exe
%System%\dllchache.exe
%System%\drivers\drivers.cab.exe
%System%\init32.exe
%System%\lphc35dj0erc1.exe
%System%\m5vbvm60.exe
%System%\mdm32.exe
%System%\msgfix.exe
%System%\msrstart.exe
%System%\mstd.exe
%System%\netvdm.exe
%System%\nxtepad.exe
%System%\olhrwef.exe
%System%\opeia.exe
%System%\reader_s.exe
%System%\regedit.exe
%System%\regsvr.exe
%System%\rund1132.exe
%System%\rvhost.exe
%System%\vamsoft.exe
%System%\vt100.exe
%System%\winsit.exe
%System%\wmdtc.exe
%Temp%\0005d568_rar\ssvichosst.exe
%Temp%\125527.exe
%Temp%\acch8gh5fscyv.exe
%Temp%\csrssc.exe
%Temp%\d3tidso8f53.exe
%Temp%\e6byepbnt3.exe
%Temp%\ebui4ng1t.exe
%Temp%\fi4b0njkqhe.exe
%Temp%\fkvpxr.exe
%Temp%\fpjgcxc.exe
%Temp%\glb1a2b.exe
%Temp%\h13wr98.exe
%Temp%\i65thbh.exe
%Temp%\ketls6p56b.exe
%Temp%\li7tsg6m73q1.exe
%Temp%\o090inf9et1.exe
%Temp%\p0kcvm5yqb.exe
%Temp%\p5wcslh.exe
%Temp%\sa7egmn9pt.exe
%Temp%\tkdazkdfuhoon.exe
%Temp%\w2izuu2ecx.exe
%Temp%\y2c77xwr2f.exe
%Temp%\ycqrdd.exe
%Temp%\zcilitfgwv.exe
%Temp%\zsyxaf6zsz.exe
%UserProfile%\reader_s.exe
%Windir%\9129837.exe
%Windir%\dc.exe
%Windir%\dhcp\svchost.exe
%Windir%\dnmee33.exe
%Windir%\help\other.exe
%Windir%\inf\other.exe
%Windir%\pchealth\global.exe
%Windir%\pchealth\helpctr\binaries\helphost.com
%Windir%\regsvr.exe
%Windir%\rvhost.exe
%Windir%\services.exe
%Windir%\svchost.exe
%Windir%\sviq.exe
%Windir%\sysguard.exe
%Windir%\system\fun.exe
%Windir%\system\keyboard.exe
%Windir%\system32.exe
%Windir%\usbservice.exe
c:\2fiji.com
c:\ms-dos.com
Notes:
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.