Threat Search: 

ThreatExpert's Statistics for Win32.Virut.Gen [PC Tools]:

Win32.Virut.Gen [PC Tools] is also known as:
Threat AliasNumber of Incidents
W32/Virut.gen [McAfee]1,614
Virus.Win32.Virut.n [Kaspersky Lab]1,440
PE_VIRUT.D [Trend Micro]596
PE_VIRUT.GEN-2 [Trend Micro]595
Virus:Win32/Virut.AK [Microsoft]582
Bloodhound.Unknown [Symantec]565
W32.Virut.B [Symantec]514
W32/Vetor-A [Sophos]438
W32/Virut-L [Sophos]186
W32/RAHack [McAfee]165
W32.Rahack.W [Symantec]154
WORM_ALLAPLE.IK [Trend Micro]154
W32/Allaple-F [Sophos]146
PE_VIRUT.GEN [Trend Micro]135
Virus.Win32.Virut.d [Kaspersky Lab]134
Virus.Win32.Virut.p [Kaspersky Lab]129
Virus.Win32.Cheburgen.a [Ikarus]121
Virus.Win32.Virut.q [Kaspersky Lab]104
PE_VIRUT.XQ [Trend Micro]102
Win32/Virut.D [AhnLab]89
Worm:Win32/Allaple.A [Microsoft]75
Win32/Virut.C [AhnLab]67
PE_VIRUT.XI [Trend Micro]60
Virus:Win32/Virut.D [Microsoft]58
W32.Virut.H [Symantec]55
W32.Virut.R [Symantec]45
W32.Spybot.Worm [Symantec]41
PE_VIRUT.XK [Trend Micro]36
Virus.Win32.Virut.n [Ikarus]31
W32.Virut!gen [Symantec]28
W32/Virut.remnants [McAfee]24
Virus:Win32/Virut.AG [Microsoft]23
Virus:Win32/Virut.AH [Microsoft]23
Virus:Win32/Virut.AN [Microsoft]22
Virus.Win32.Cheburgen [Ikarus]21
Virus.Win32.Virut.q [Ikarus]21
Virus.Win32.Virut [Ikarus]20
Backdoor.Trojan [Symantec]19
W32.IRCBot [Symantec]18
Virus.Win32.Sality [Ikarus]11
VirTool.Win32.DelfInject [Ikarus]9
Backdoor:Win32/Poebot.BA [Microsoft]8
Backdoor:Win32/Poebot.BG [Microsoft]8
Mal_Virut-2 [Trend Micro]8
Virus.Win32.Virut.bo [Ikarus]8
W32.Linkbot.M [Symantec]8
W32/Sdbot.worm.gen.q [McAfee]8
Win32.Virtob.2 [Ikarus]8
WORM_RBOT.GDY [Trend Micro]8
Backdoor:Win32/Poebot.AT [Microsoft]7
Generic FakeAlert.d [McAfee]7
Net-Worm.Win32.Allaple.b [Kaspersky Lab]7
PE_VIRUT.A [Trend Micro]7
Virus.Win32.Virut.m [Kaspersky Lab]7
W32/Virut.a [McAfee]7
W32/Virut-T [Sophos]7
Worm:Win32/Kulsibot.A [Microsoft]7
Backdoor.Sdbot [Symantec]6
Backdoor.Win32.Rbot.bni [Kaspersky Lab]6
FakeAlert-AG.gen.c [McAfee]6
Mal/Behav-164, Mal/Dorf-D, Mal/TibsPak [Sophos]6
Net-Worm.Win32.Allaple.a [Ikarus]6
Backdoor.Win32.IRCBot [Ikarus]5
Downloader [Symantec]5
Mal/Generic-A [Sophos]5
Net-Worm.Win32.Allaple [Ikarus]5
PE_Chir.B [Trend Micro]5
PE_VIRUT.GEN-3 [Trend Micro]5
Trojan.Horse.AZT [Ikarus]5
Trojan-Dropper.Agent [Ikarus]5
Trojan-Dropper.Kobcka [Ikarus]5
W32/Chir.b@MM [McAfee]5
W32/Chir-B [Sophos]5
W32/Sdbot.worm.gen.ci [McAfee]5
Win32/IRCBot.worm.variant [AhnLab]5
Packer.RLPack.D [Ikarus]4
Trojan Horse [Symantec]4
Trojan-Downloader.Win32.Small [Ikarus]4
Trojan-Spy.Win32.Banker.RM [Ikarus]4
Virus.Win32.Virtob [Ikarus]4
W32.Chir.B@mm [Symantec]4
W32.Rahack.H [Symantec]4
W32.SillyFDC [Symantec]4
Backdoor.Win32.VanBot.wv [Kaspersky Lab]3
Email-Worm.Win32.Runouce.B [Ikarus]3
Email-Worm.Win32.Runouce.b [Kaspersky Lab]3
Exploit-DcomRpc.gen [McAfee]3
Generic.Sdbot [Ikarus]3
Mal/Allaple-A [Sophos]3
Mal/Dorf-A, W32/Vetor-A [Sophos]3
Net-Worm.Win32.Allaple.e [Kaspersky Lab]3
New Malware.gm [McAfee]3
Packer.RLPack [Ikarus]3
PE_VIRUT.WY [Trend Micro]3
Trojan.Win32.Anomaly.D [Ikarus]3
Trojan.Win32.Banker [Ikarus]3
Trojan.Win32.Pakes [Ikarus]3
Trojan-Dropper.Win32.Cutwail.AL [Ikarus]3
Trojan-Proxy.Win32.Slaper.n [Kaspersky Lab]3
VirTool.Win32.Injector.D [Ikarus]3

Win32.Virut.Gen [PC Tools] has the following possible countries of origin:
OriginNumber of Incidents
China56
Germany38
Netherlands37
Russian Federation19
France17
United Kingdom9
Israel7
Italy7
Spain7
Czech Republic6
Poland6
Portugal6
Sweden6
Taiwan5
Brazil4
Australia2
Denmark2
Iran2
Japan2
Republic of Korea2
Thailand2
Turkey2
Belgium1
Finland1
Saudi Arabia1
Slovakia1
Ukraine1

Win32.Virut.Gen [PC Tools] is known to be created as:
%AllUsersProfile%\documents.exe
%AllUsersProfile%\favorites.exe
%AppData%\csrss.exe
%AppData%\inetinfo.exe
%AppData%\lsass.exe
%AppData%\services.exe
%AppData%\smss.exe
%AppData%\winlogon.exe
%CommonDocuments%\documents.exe
%CommonFavorites%\favorites.exe
%CommonPrograms%\accessories.exe
%CommonPrograms%\accessories\accessibility.exe
%CommonPrograms%\accessories\accessibility\accessibility.exe
%CommonPrograms%\accessories\accessories.exe
%CommonPrograms%\programs.exe
%CommonPrograms%\startup\autorun.exe
%CommonPrograms%\startup\lsass.exe
%CommonPrograms%\startup\msconfig.exe
%CommonStartMenu%\programs.exe
%DesktopDir%\desktop.exe
%FontsDir%\fonts.exe
%FontsDir%\internat.exe
%FontsDir%\tskmgr.exe
%FontsDir%\unwise_.exe
%ProgramFiles%\common files\system\ado\tsektjkj.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\common files\system\msiwa32.exe
%ProgramFiles%\common files\system\mswvr32.exe
%ProgramFiles%\getpack\getpack22.exe
%ProgramFiles%\icheck\icheck.exe
%ProgramFiles%\javacore\javacore.exe
%ProgramFiles%\javacore\uninstall.exe
%ProgramFiles%\meex.exe
%ProgramFiles%\messenger.exe
%ProgramFiles%\messenger\messenger.exe
%ProgramFiles%\microsoft frontpage\version3.0.exe
%ProgramFiles%\microsoft frontpage\version3.0\bin.exe
%ProgramFiles%\microsoft frontpage\version3.0\bin\bin.exe
%ProgramFiles%\microsoft frontpage\version3.0\version3.0.exe
%ProgramFiles%\netmeeting.exe
%ProgramFiles%\netmeeting\netmeeting.exe
%ProgramFiles%\netmeeting\rsewzjqn.exe
%ProgramFiles%\nvcoi\nvcoi.exe
%ProgramFiles%\thunmail\testabd.exe
%ProgramFiles%\vmware.exe
%ProgramFiles%\xerox.exe
%ProgramFiles%\xerox\nwwia.exe
%ProgramFiles%\xerox\nwwia\nwwia.exe
%ProgramFiles%\xerox\xerox.exe
%ProgramFiles%\xpcode\sexgame.exe
%ProgramFiles%\xpcode\sexscreensaver.scr
%Programs%\startup\findfast.exe
%Programs%\startup\msn.exe
%System%\116376534862l.exe
%System%\28463\kytc.exe
%System%\332.exe
%System%\3361\svchost.exe
%System%\3fabe9c0.exe
%System%\451621078306l.exe
%System%\4e17c240.exe
%System%\551621078316l.exe
%System%\8040\8040.exe
%System%\8040\data.exe
%System%\8040\lsass.exe
%System%\8040\svchost.exe
%System%\algs.exe
%System%\amvo.exe
%System%\autochl.exe
%System%\blphc35dj0erc1.scr
%System%\botfile.exe
%System%\brie.exe
%System%\com\lsass.exe
%System%\com\smss.exe
%System%\csrs.exe
%System%\csrsc.exe
%System%\ddspb.exe
%System%\dkvlbkndc.exe
%System%\dllcache\cvchost.exe
%System%\dllcache\cychost.exe
%System%\dllcache\default.exe
%System%\dllcache\freewin.exe
%System%\dllcache\global.exe
%System%\dllcache\log.exe
%System%\dllcache\newhost.exe
%System%\dllcache\qsch0st.exe
%System%\dllcache\rndll32.exe
%System%\dllcache\rtsecar.exe
%System%\dllcache\svchost.exe
%System%\dllcache\svqhost.exe
%System%\dllcache\sxch0st.exe
%System%\dllcache\sxchost.exe
%System%\dllcache\tskmgr.exe
%System%\dllcache\vvvhost.exe
%System%\dllcache\windmns.exe
%System%\dllcache\wingptd.exe
%System%\dllcache\winsop.exe
%System%\dllcache\wintcpack.exe
%System%\dllcache\wintcps.exe
%System%\dllcache\zipexr.dll
%System%\down.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonDocuments% is a variable that refers to the file system directory that contains documents that are common to all users. A typical paths is C:\Documents and Settings\All Users\Documents.
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %CommonStartMenu% is a variable that refers to the file system directory that contains the programs and folders that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu (Windows NT/2000/XP).
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).