Threat Search: 

ThreatExpert's Statistics for Win32/Virut.F [AhnLab]:

Win32/Virut.F [AhnLab] is also known as:
Threat AliasNumber of Incidents
Virus.Win32.Virut.ce [Kaspersky Lab]2,222
W32.Virut.CF [Symantec]2,131
W32/Scribble-B [Sophos]2,074
Virus:Win32/Virut.BM [Microsoft]1,841
W32/Virut.n.gen [McAfee]1,407
New Win32 [McAfee]497
Malware.Virut [PC Tools]467
Virus:Win32/Virut.gen!O [Microsoft]223
Virus.Win32.Sality [Ikarus]121
W32/Virut.n [McAfee]116
Mal/HckPk-A, W32/Scribble-B [Sophos]90
New Poly Win32 [McAfee]86
Virus:Win32/Virut.gen!E [Microsoft]75
Virus.Win32.Bifrose [Ikarus]66
PE_VIRUX.H-3 [Trend Micro]58
Mal/Bifrose-S, W32/Scribble-B [Sophos]53
PE_VIRUX.E-2 [Trend Micro]51
Virus.Win32.Virut [Ikarus]46
Trojan-Banker.Win32.Bancos [Ikarus]37
PE_VIRUX.A-1 [Trend Micro]33
Trojan-Downloader.Win32.Agent.czsd [Kaspersky Lab]32
BackDoor-CEP.gen.au [McAfee]31
PE_VIRUX.E-3 [Trend Micro]31
Spam-Mailbot [McAfee]31
not-a-virus:Porn-Dialer.Win32.Agent.bk [Ikarus]29
Trojan-Downloader.Win32.Cutwail [Ikarus]21
Virus.Virut.j [PC Tools]21
PE_VIRUX.F-3 [Trend Micro]20
New Win32.g2 [McAfee]18
Mal/HckPk-A [Sophos]17
Mal/Scribble-C, W32/Scribble-B [Sophos]17
Trojan:Win32/Puzlice.A [Microsoft]16
TrojanDropper:Win32/Puzlice.A [Microsoft]16
Trojan-Spy.Win32.VB [Ikarus]16
Backdoor.Win32.Bifrose [Ikarus]14
W32/Scribble-A [Sophos]13
Packed.Win32.Koblu [Ikarus]12
Trojan Horse [Symantec]12
Virus.Win32.JunkPoly [Ikarus]12
Generic PWS.ak [McAfee]11
Mal/Generic-A [Sophos]11
PWS-Banker [McAfee]11
Trojan.Win32.Agent2.hxw [Kaspersky Lab]11
VirTool.Win32.DelfInject [Ikarus]11
Mal/Bifrose-S, Mal/Bifrose-S, W32/Scribble-B [Sophos]10
TrojanProxy:Win32/Slenugga.A [Microsoft]10
W32.SillyFDC [Symantec]10
Spy-Agent.bv.gen.b [McAfee]9
Trojan-Clicker.Win32.Delf [Ikarus]9
Trojan-Clicker.Win32.VB [Ikarus]9
Downloader [Symantec]8
Email-Worm.Win32.Mydoom.bj [Ikarus]8
PE_VIRUX.J-4 [Trend Micro]8
W32.Mytob@mm [Symantec]8
Backdoor.Win32.Refpron [Ikarus]7
Mal/Behav-043, W32/Scribble-B [Sophos]7
New Malware.fa [McAfee]7
Packed.Win32.Krap.b [Kaspersky Lab]7
Spammer [Ikarus]7
Trojan.Agent.DEL [PC Tools]7
Trojan.Win32.VB [Ikarus]7
Trojan-Downloader.Win32.Zlob [Ikarus]7
Trojan-Dropper [Ikarus]7
W32/DelpBck-Gen [Sophos]7
Backdoor.Win32.Beastdoor [Ikarus]6
Exploit.Win32.IMG-WMF [Ikarus]6
New Malware.bj [McAfee]6
Trojan.Fakeavalert [Symantec]6
Trojan:Win32/Winwebsec [Microsoft]6
TrojanDownloader:Win32/Cutwail.gen!C [Microsoft]6
Trojan-Dropper.VB.ggm [PC Tools]6
Virus.Win32.Virut.n [Ikarus]6
Worm:Win32/Taterf.B [Microsoft]6
Backdoor.Win32.Popwin [Ikarus]5
Backdoor:Win32/Refpron.M [Microsoft]5
Mal/EncPk-FS, W32/Scribble-B [Sophos]5
PE_VIRUX.D-1 [Trend Micro]5
Trojan-Clicker.VB.cwf [PC Tools]5
Trojan-Clicker.Win32.VB.cvg [Ikarus]5
Trojan-Downloader.LoadAdv [Ikarus]5
Trojan-Dropper.Agent [Ikarus]5
Trojan-PWS.Win32.LdPinch [Ikarus]5
Virus.W32.Sality [Ikarus]5
Virus.Win32.Virtob [Ikarus]5
Virus:Win32/Virut.gen!M [Microsoft]5
W32.Imaut [Symantec]5
W32.IRCBot [Symantec]5
Win32.SuspectCrc [Ikarus]5
Backdoor.Bifrose.AHY [PC Tools]4
Backdoor.Rustock [Ikarus]4
Backdoor.Win32.PoisonIvy.az [Ikarus]4
BackDoor-CEP.svr [McAfee]4
BKDR_BIFROSE.MIC [Trend Micro]4
Mal/Behav-103, Mal/Behav-043, W32/Scribble-B [Sophos]4
Mal/EncPk-JB, W32/Scribble-B [Sophos]4
P2P-Worm.Win32.Palevo [Ikarus]4
PE_VIRUX.J-3 [Trend Micro]4
Suspicious.MH690 [Symantec]4
Trojan.Autoit [Ikarus]4
Trojan.Midgare.EYZ [PC Tools]4

Win32/Virut.F [AhnLab] has the following possible countries of origin:
OriginNumber of Incidents
China374
Russian Federation134
Sweden92
Germany41
United Kingdom32
Spain25
Saudi Arabia14
France10
Poland10
Brazil9
Italy8
Belgium7
Israel7
Turkey7
Australia5
Taiwan5
Egypt4
Portugal4
Netherlands3
Finland2
Hungary2
Iraq2
Jordan2
Austria1
Canada1
Chile1
Czech Republic1
Greece1
Iran1
Lebanon1
Norway1
Republic of Korea1
Slovenia1

Win32/Virut.F [AhnLab] is known to be created as:
%AllUsersProfile%\desktop.exe
%AllUsersProfile%\favorites.exe
%AppData%\converter7.exe
%AppData%\csrss.exe
%AppData%\e4u.exe
%CommonAppData%\11540624\11540624.exe
%CommonAppData%\11548124\11548124.exe
%CommonAppData%\11550464\11550464.exe
%CommonAppData%\11551254\11551254.exe
%CommonAppData%\11559214\11559214.exe
%CommonAppData%\11593434\11593434.exe
%CommonDesktopDir%\desktop.exe
%CommonFavorites%\favorites.exe
%CommonPrograms%\startup\startup.exe
%DesktopDir%\desktop.exe
%FontsDir%\fonts.exe
%FontsDir%\logcde.dll
%FontsDir%\services.exe
%FontsDir%\svchost.exe
%FontsDir%\tskmgr.exe
%FontsDir%\unwise_.exe
%FontsDir%\windef.dll
%LocalSettings%\carbon.exe
%LocalSettings%\tempkey.exe
%ProgramFiles%\advancedvirusremover\pavrm.exe
%ProgramFiles%\alphaant\alpha.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\sosue.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\freevpn\freevpn.exe
%ProgramFiles%\gamazer.3.exe
%ProgramFiles%\internet explorer\mui.exe
%ProgramFiles%\internet explorer\mui\0409.exe
%ProgramFiles%\internet explorer\mui\0409\0409.exe
%ProgramFiles%\internet explorer\mui\mui.exe
%ProgramFiles%\meex.exe
%ProgramFiles%\messenger.exe
%ProgramFiles%\messenger\messenger.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\microsoft office\winword.exe
%ProgramFiles%\mirc\irc bot\services.exe
%ProgramFiles%\movie maker\svchost.exe
%ProgramFiles%\netmeeting.exe
%ProgramFiles%\netmeeting\netmeeting.exe
%ProgramFiles%\no-ip\duc20.exe
%ProgramFiles%\thunmail\testabd.exe
%ProgramFiles%\windows media player\skins.exe
%ProgramFiles%\windows media player\skins\skins.exe
%ProgramFiles%\windows\csrss.exe
%ProgramFiles%\winpcap.exe
%ProgramFiles%\winpcap\winpcap.exe
%Programs%\startup\f46b2.exe.exe
%System%\.00cd1a40\00cd1a40.exe
%System%\1054v.exe
%System%\1061044.exe
%System%\1114878.exe
%System%\1124216.exe
%System%\1163889.exe
%System%\1392618.exe
%System%\1438649.exe
%System%\1472391.exe
%System%\1502472.exe
%System%\155309.exe
%System%\1587167.exe
%System%\1673281.exe
%System%\1772553.exe
%System%\1775869.exe
%System%\1949257.exe
%System%\2501627.exe
%System%\2713724.exe
%System%\2851786.exe
%System%\28892.exe
%System%\294748.exe
%System%\2985758.exe
%System%\3216959.exe
%System%\3361\svchost.exe
%System%\3362833.exe
%System%\3429789.exe
%System%\3555246.exe
%System%\3649343.exe
%System%\3780283.exe
%System%\3824534.exe
%System%\3827158.exe
%System%\3833211.exe
%System%\3955942.exe
%System%\3967233.exe
%System%\3976359.exe
%System%\4067301.exe
%System%\4121012.exe
%System%\4337687.exe
%System%\4348703.exe
%System%\4350657.exe
%System%\4358164.exe
%System%\4548869.exe
%System%\4662394.exe
%System%\467663.exe
%System%\5220132.exe
%System%\5510813.exe
%System%\5556131.exe
%System%\5581308.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).