Threat Search: 

ThreatExpert's Statistics for WORM_IMAUT.E [Trend Micro]:

WORM_IMAUT.E [Trend Micro] is also known as:
Threat AliasNumber of Incidents
Worm.Hakaglan.B [PC Tools]177
W32.Yautoit.N [Symantec]138
Worm.Win32.AutoIt.c [Kaspersky Lab]124
W32/Cocung.worm [McAfee]68
Downloader-FL [McAfee]63
IM-Worm.Win32.Sohanad.bm [Kaspersky Lab]56
W32/SillyFDC-G [Sophos]51
W32.Imaut.N [Symantec]41
IM-Worm.Win32.Sohanad [Ikarus]27
Worm:Win32/Nuqel.A [Microsoft]25
W32/YahLover.worm [McAfee]19
Win32/Autoit.worm.268216 [AhnLab]18
IM-Worm.Win32.Sohanad.t [Kaspersky Lab]17
Worm:Win32/Agent.F [Microsoft]17
Virus.Win32.Hakaglan [Ikarus]13
Worm.AutoIt!sd5 [PC Tools]11
W32.Yautoit [Symantec]10
W32/YahLover.worm.gen [McAfee]9
Worm.Sohanad.P [PC Tools]9
Worm.Win32.AutoIt.e [Kaspersky Lab]9
IM-Worm.Win32.Sohanad.gen [Kaspersky Lab]8
W32.SillyFDC [Symantec]8
W32/Hakaglan.worm.gen [McAfee]8
Worm:Win32/Sohonad [Microsoft]6
W32/Fujacks [McAfee]4
Worm.Sohanad.Y [PC Tools]4
W32.Imaut [Symantec]3
Worm.Win32.AutoRun.fwl [Kaspersky Lab]3
Backdoor.Trojan [Symantec]2
IM-Worm.Win32.Sohanad.ei [Kaspersky Lab]2
Mal/Airworm-A [Sophos]2
Mal/Sohana-A [Sophos]2
Virus.Win32.AutoIt.g [Kaspersky Lab]2
W32.Svich [Symantec]2
W32/Sohana-AC [Sophos]2
Win32/Hakaglan.worm.263168 [AhnLab]2
Worm.IMWorm.BF [PC Tools]2
Worm:Win32/Nuqel.B [Microsoft]2
Worm:Win32/Sohanad.M [Microsoft]2
Bloodhound.Unknown [Symantec]1
Downloader-AZG [McAfee]1
Generic BackDoor.u [McAfee]1
Generic.ed [McAfee]1
Generic.ep [McAfee]1
IM-Worm.Sohanad!sd5 [PC Tools]1
Troj/Tiotua-D [Sophos]1
Trojan Horse [Symantec]1
Virus.Win32.Virut.n [Kaspersky Lab]1
Virus:Win32/Mabezat.B [Microsoft]1
W32.Imaut.BH [Symantec]1
W32.Imaut.CN [Symantec]1
W32/Mabezat.a [McAfee]1
W32/Mabezat-B [Sophos]1
W32/Virut.remnants [McAfee]1
Win32.Dzan.A [PC Tools]1
Worm.Win32.Mabezat.b [Kaspersky Lab]1
Worm:Win32/Nhatq [Microsoft]1
Worm:Win32/Nuqel.C [Microsoft]1
Worm:Win32/Nuqel.P [Microsoft]1

WORM_IMAUT.E [Trend Micro] has the following possible countries of origin:
OriginNumber of Incidents
United Kingdom203
Saudi Arabia1

WORM_IMAUT.E [Trend Micro] is known to be created as:
%System%\rvhiost.exe
%System%\rvhost.exe
%System%\scvhost.exe
%System%\svichossst.exe
%System%\svichosst.exe
%Temp%\00053262_rar\rvhost.exe
%Temp%\00058fe3_rar\rvhost.exe
%Temp%\00058ff3_rar\rvhost.exe
%Temp%\00059002_rar\rvhost.exe
%Temp%\00059031_rar\rvhost.exe
%Temp%\00059496_rar\rvhost.exe
%Temp%\0005d410_rar\rvhost.exe
%Temp%\0005d430_rar\rvhost.exe
%Temp%\0005d7f8_rar\rvhost.exe
%Temp%\0005d8d3_rar\rvhost.exe
%Temp%\00214cd7_rar\rvhost.exe
%Windir%\rvhiost.exe
%Windir%\rvhost.exe
%Windir%\scvhost.exe
%Windir%\svichossst.exe
%Windir%\svichosst.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.