Threat Search: 

ThreatExpert's Statistics for W32.Virut.W [Symantec]:

W32.Virut.W [Symantec] is also known as:
Threat AliasNumber of Incidents
Win32.Virut.Gen.4 [PC Tools]570
W32/Virut.gen.a [McAfee]550
PE_VIRUT.AV [Trend Micro]416
W32/Virut-W [Sophos]407
Virus.Win32.Virut.av [Kaspersky Lab]375
Virus:Win32/Virut.AC [Microsoft]371
Win32/Virut.B [AhnLab]322
W32/Virut.j [McAfee]232
W32/Virut-Gen [Sophos]211
Virus.Win32.Virut.av [Ikarus]117
PE_VIRUT.AP [Trend Micro]95
Virus:Win32/Virut.BI [Microsoft]94
Virus.Win32.Sality [Ikarus]89
Win32/Virut.Gen [AhnLab]69
W32/Virut-X [Sophos]64
Virus:Win32/Virut.AU [Microsoft]59
PE_VIRUT.BA [Trend Micro]58
Virus.Win32.Virut.bx [Kaspersky Lab]56
Mal/HckPk-A, W32/Virut-Gen [Sophos]51
PE_VIRUT.AT [Trend Micro]45
Virus.Win32.Virut.bw [Kaspersky Lab]44
Virus:Win32/Virut.AA [Microsoft]44
PE_VIRUT.JN [Trend Micro]40
Virus.Win32.Virut.at [Kaspersky Lab]39
Virus.Win32.Virut.au [Ikarus]39
Virus.Win32.Virut.as [Kaspersky Lab]38
PE_VIRUT.LJ [Trend Micro]34
PE_VIRUT.YE [Trend Micro]34
Virus.Win32.Virut.bu [Kaspersky Lab]34
Virus.Win32.Virut.bq [Kaspersky Lab]31
W32/Vetor-G [Sophos]31
Win32/Virut [AhnLab]31
Virus:Win32/Virut.BG [Microsoft]30
Packer.RLPack [Ikarus]28
PE_VIRUT.CEL [Trend Micro]27
Virus.Win32.Virut.be [Kaspersky Lab]27
Win32.Virut.U [Ikarus]26
W32/Virut.h [McAfee]25
PE_VIRUT.XV [Trend Micro]23
Backdoor.Win32.Nepoe.em [Kaspersky Lab]22
Backdoor:Win32/Rbot [Microsoft]22
Virus.Win32.Virut.ac [Kaspersky Lab]22
Virus:Win32/Virut.gen!AI [Microsoft]22
W32/Virut [McAfee]22
Worm.SdBot.GAP [PC Tools]22
Virus:Win32/Virut.T [Microsoft]21
W32/Virut-R [Sophos]21
W32/Virut-T [Sophos]21
Trojan.Crypt.NSPM [Ikarus]19
PE_VIRUT.YC [Trend Micro]17
Spam-Mailbot [McAfee]17
Virus.Win32.Virut.bv [Kaspersky Lab]17
Net-Worm.Win32.Bobic.dq [Kaspersky Lab]15
Packer.RLPack.D [Ikarus]15
Virus.Win32.Virut.ao [Kaspersky Lab]15
Virus:Win32/Virut.Q [Microsoft]15
Worm.Bobax.AB [PC Tools]15
PE_VIRUT.PAU [Trend Micro]14
Virus:Win32/Virut.AB [Microsoft]14
Virus:Win32/Virut.BF [Microsoft]14
PE_VIRUT.XZ [Trend Micro]13
Virus.Win32.Virut.af [Kaspersky Lab]13
Virus:Win32/Virut.BA [Microsoft]13
Trojan-Proxy.Win32.Slaper.n [Ikarus]12
Virus.Win32.Virut [Ikarus]12
Virus.Win32.Virut.n [Ikarus]12
Virus:Win32/Virut.X [Microsoft]12
W32/Virut-V [Sophos]12
Backdoor:Win32/Poebot.AT [Microsoft]11
Virus.Win32.Virut.y [Kaspersky Lab]11
Backdoor:Win32/Poebot.BA [Microsoft]10
PE_VIRUT.XU [Trend Micro]10
PE_VIRUT.YD [Trend Micro]10
Virus.Win32.Virut.ai [Kaspersky Lab]10
Virus.Win32.Virut.ar [Kaspersky Lab]10
Virus.Win32.Virut.bf [Kaspersky Lab]10
Virus.Win32.Virut.u [Kaspersky Lab]10
Virus:Win32/Virut.U [Microsoft]10
Virus:Win32/Virut.V [Microsoft]10
Virus:Win32/Virut.Z [Microsoft]10
W32/Vetor-H [Sophos]10
W32/Virut.g [McAfee]10
PE_VIRUT.NZY [Trend Micro]9
Trojan-Downloader.Win32.Small [Ikarus]9
Virus.Win32.Virut.bo [Kaspersky Lab]9
Net-Worm.Win32.Padobot.m [Kaspersky Lab]8
VirTool.Win32.DelfInject [Ikarus]8
VirTool.Win32.VBInject [Ikarus]8
Virus.Virut.AV [PC Tools]8
Virus.Win32.Virut.ao [Ikarus]8
Virus.Win32.Virut.n [Kaspersky Lab]8
Virus.Win32.Virut.t [Kaspersky Lab]8
W32/Virut.i [McAfee]8
Worm:Win32/Korgo.V [Microsoft]8
Net-Worm.Win32.Kolabc [Ikarus]7
PE_VIRUT.AUD [Trend Micro]7
Trojan-Downloader.Win32.Pakernat.A [Ikarus]7
Virus.Trojan.Win32.VB [Ikarus]7
Virus.Win32.Virut.aw [Kaspersky Lab]7
Virus.Win32.Virut.bt [Kaspersky Lab]7

W32.Virut.W [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
Germany24
China21
Russian Federation12
Netherlands11
Sweden10
Republic of Korea6
Spain6
France5
Brazil4
Taiwan4
Italy3
Poland3
Turkey3
Ukraine3
Australia2
Belgium2
Israel2
Saudi Arabia2
United Kingdom2
Finland1
Hungary1
Iran1
Portugal1
Slovenia1

W32.Virut.W [Symantec] is known to be created as:
%AppData%\facegame\facegame.exe
%CommonAppData%\cfunilcb\arenqnqd.exe
%CommonAppData%\tmbgvinu\hqfulore.exe
%DesktopDir%\desktop.exe
%Favorites%\favorites.exe
%FontsDir%\unwise_.exe
%Profiles%\localservice\services.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\meex.exe
%ProgramFiles%\windows nt\lsass.exe
%System%\%computername%\svchost.exe
%System%\1025\1025.exe
%System%\1028\1028.exe
%System%\1031\1031.exe
%System%\1033\1033.exe
%System%\1037\1037.exe
%System%\1041\1041.exe
%System%\1042\1042.exe
%System%\1054\1054.exe
%System%\2052\2052.exe
%System%\3076\3076.exe
%System%\3com_dmi\3com_dmi.exe
%System%\abdri.exe
%System%\algs.exe
%System%\amvo.exe
%System%\ancpkyckttc.exe
%System%\autochl.exe
%System%\bgadpdpd.exe
%System%\bifrost.exe
%System%\blastclnnn.exe
%System%\bqzztzjnz.exe
%System%\bro_act1.exe
%System%\bttnserv.exe
%System%\catroot\catroot.exe
%System%\catroot2\catroot2.exe
%System%\cbevtsvc.exe
%System%\cilevb.com
%System%\ckvo.exe
%System%\clock.exe
%System%\cmd.com
%System%\com\com.exe
%System%\com\lsass.exe
%System%\cpl32ver.exe
%System%\cpu.exe
%System%\csrcs.exe
%System%\csrs.exe
%System%\csrsc.exe
%System%\ctfmom.exe
%System%\cucjuw.exe
%System%\dhcp\dhcp.exe
%System%\directx\directx.exe
%System%\dj-dn.exe
%System%\dllcache\log.exe
%System%\dn.exe
%System%\drivers\drivers.exe
%System%\drivers\drsch.exe
%System%\drivers\nvidiaa\services.exe
%System%\drivers\nvidiaa\wget.exe
%System%\drivers\smss.exe
%System%\drivers\svchost.exe
%System%\dxdiag.com
%System%\dxgdialog.exe
%System%\ekdfmemrwdpksi.exe
%System%\erurz.exe
%System%\exlorers.exe
%System%\explorer.exe
%System%\export\export.exe
%System%\firewall.exe
%System%\flash.10.exe
%System%\godydd.exe
%System%\gyrayqu.exe
%System%\hpctxeb.exe
%System%\hqamqrji.exe
%System%\hrrttdbbaggo.exe
%System%\ias\ias.exe
%System%\icsxml\icsxml.exe
%System%\iexplore.exe
%System%\iexplorer.exe
%System%\igxdfdfds.com
%System%\ime\ime.exe
%System%\inetsrv\inetsrv.exe
%System%\install.exe
%System%\ipodfixer.exe
%System%\isass.exe
%System%\itrycrm.exe
%System%\j3ewro.exe
%System%\jambanmu.com
%System%\kamsoft.exe
%System%\kjiqqji.exe
%System%\lap.exe
%System%\lfbjaerus.exe
%System%\logon.exe
%System%\lphc35dj0erc1.exe
%System%\lssas.exe
%System%\macromed\macromed.exe
%System%\msconfig.com
%System%\msdtc\msdtc.exe
%System%\msnclicfg.exe
%System%\msnmsgr.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %Favorites% is a variable that refers to the file system directory that serves as a common repository for the user's favorite items. A typical path is C:\Documents and Settings\[UserName]\Favorites.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %ComputerName% is a variable that refers to the current computer name.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).