Threat Search: 

ThreatExpert's Statistics for W32.Yautoit.N [Symantec]:

W32.Yautoit.N [Symantec] is also known as:
Threat AliasNumber of Incidents
Worm.Hakaglan.B [PC Tools]145
WORM_IMAUT.E [Trend Micro]138
Worm.Win32.AutoIt.c [Kaspersky Lab]114
W32/Cocung.worm [McAfee]55
Downloader-FL [McAfee]44
W32/YahLover.worm [McAfee]31
Worm.Sohanad.Z [PC Tools]31
WORM_SOHANAD.EK [Trend Micro]31
IM-Worm.Win32.Sohanad.ap [Kaspersky Lab]30
IM-Worm.Win32.Sohanad.bm [Kaspersky Lab]17
JS.Chir.B [PC Tools]14
PE_Chir.B [Trend Micro]13
W32/Chir.b@MM [McAfee]13
Email-Worm.Win32.Runouce.b [Kaspersky Lab]12
IM-Worm.Win32.Sohanad.ao [Kaspersky Lab]12
W32.Imaut.N [Symantec]12
WORM_SOHANAD.BA [Trend Micro]12
IM-Worm.Win32.Sohanad [Ikarus]11
IM-Worm.Win32.Sohanad.t [Kaspersky Lab]9
Worm.Win32.AutoIt.e [Kaspersky Lab]8
W32/SillyFDC-G [Sophos]7
Worm.AutoIT.AL [PC Tools]7
IM-Worm.Sohanad!sd5 [PC Tools]6
W32/Hakaglan.worm.gen [McAfee]6
Worm.AutoIt!sd5 [PC Tools]6
W32/Fujacks [McAfee]5
W32/Virut.gen [McAfee]5
Worm.Agent.EQAV [PC Tools]5
Worm:Win32/Sohanad.I [Microsoft]5
Trojan.Win32.Agent.cru [Kaspersky Lab]4
Worm.Agent.EQGP [PC Tools]4
PE_VIRUT.GEN [Trend Micro]3
Virus.Win32.Virut.n [Kaspersky Lab]3
W32/Sohana-W [Sophos]3
Win32/Sohanad.worm.244590 [AhnLab]3
Worm.Sohanad.P [PC Tools]3
Worm:Win32/Agent.F [Microsoft]3
Worm:Win32/Sohonad [Microsoft]3
WORM_SILLYFDC.B [Trend Micro]3
WORM_VB.BC [Trend Micro]3
Generic.ed [McAfee]2
PE_PARITE.A [Trend Micro]2
Virus.Win32.Parite.b [Kaspersky Lab]2
W32/Pate.b [McAfee]2
W32/Sohana-AS [Sophos]2
Win32/Autoit.worm.268216 [AhnLab]2
Worm.AutoRun.ADQ [PC Tools]2
Worm.Sohanad.R [PC Tools]2
WORM_SOHANAD.BO [Trend Micro]2
WORM_SOHANAD.DW [Trend Micro]2
Downloader-AZG [McAfee]1
Downloader-AZG.dr [McAfee]1
Generic.ep [McAfee]1
IM-Worm.Win32.Sohanad.ei [Kaspersky Lab]1
PE_DZAN.C [Trend Micro]1
PE_MUMAWOW.AE [Trend Micro]1
PE_SALITY.AL [Trend Micro]1
PE_VIRUT.AV [Trend Micro]1
PE_VIRUT.XP [Trend Micro]1
Virus.Win32.Dzan.c [Kaspersky Lab]1
Virus.Win32.Sality.s [Kaspersky Lab]1
Virus.Win32.Virut.d [Kaspersky Lab]1
Virus.Win32.Virut.q [Kaspersky Lab]1
W32/Dzan.c [McAfee]1
W32/Mabezat.a [McAfee]1
W32/MumaWow.c!inf [McAfee]1
W32/Sality.ac [McAfee]1
W32/Virut.gen.a [McAfee]1
W32/Virut.remnants [McAfee]1
Worm.Sohanad.J [PC Tools]1
Worm.Sohanad.U [PC Tools]1
Worm:Win32/Sohanad.M [Microsoft]1
WORM_AGENT.LRC [Trend Micro]1
WORM_Generic [Trend Micro]1
WORM_HAKAGLAN.B [Trend Micro]1
WORM_IMAUT.O [Trend Micro]1
WORM_SILLYFDC.AC [Trend Micro]1
WORM_SOHANAD.AN [Trend Micro]1
WORM_SOHANAD.AO [Trend Micro]1
WORM_SOHANAD.CL [Trend Micro]1
WORM_SOHANAD.FQ [Trend Micro]1

W32.Yautoit.N [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
United Kingdom210
Saudi Arabia1

W32.Yautoit.N [Symantec] is known to be created as:
%System%\blastclnnn.exe
%System%\rvhost.exe
%System%\scvshosts.exe
%System%\sscvihost.exe
%System%\sscvihost.exe.exe
%System%\ssvichosst.exe
%System%\svichossst.exe
%System%\svichosst.exe
%System%\sviichost.exe
%Temp%\00058ff3_rar\rvhost.exe
%Temp%\00059002_rar\rvhost.exe
%Temp%\00059031_rar\rvhost.exe
%Temp%\00059245_rar\sscvihost.exe
%Temp%\00059293_rar\sscvihost.exe
%Temp%\000594e4_rar\rvhost.exe
%Temp%\0005d3b3_rar\sscvihost.exe
%Temp%\0005d410_rar\rvhost.exe
%Temp%\0005d7aa_rar\sscvihost.exe
%Temp%\0005d7f8_rar\rvhost.exe
%Temp%\0005dcda_rar\sscvihost.exe
%Temp%\00214cd7_rar\rvhost.exe
%Windir%\hinhem.scr
%Windir%\rvhost.exe
%Windir%\scvshosts.exe
%Windir%\sscvihost.exe
%Windir%\ssvichosst.exe
%Windir%\svichossst.exe
%Windir%\svichosst.exe
%Windir%\sviichost.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.