Threat Search: 

ThreatExpert's Statistics for Worm.Win32.Hamweq [Ikarus]:

Worm.Win32.Hamweq [Ikarus] is also known as:
Threat AliasNumber of Incidents
Worm:Win32/Hamweq.gen!C [Microsoft]84
WORM_HAMWEQ.BU [Trend Micro]63
Worm:Win32/Hamweq.A [Microsoft]54
W32.SillyFDC [Symantec]52
W32/Autoham-Fam [Sophos]36
W32.Ircbrute [Symantec]27
Worm.Hamweg.Gen [PC Tools]25
Generic.dx [McAfee]22
W32/Autorun.worm.gen [McAfee]18
W32.IRCBot [Symantec]16
Win-Trojan/Agent.13824.FE [AhnLab]14
W32.Sality.AE [Symantec]11
W32/Sality-AM [Sophos]11
Virus:Win32/Sality.AM [Microsoft]10
Backdoor.Trojan [Symantec]9
Trojan Horse [Symantec]8
Virus.Win32.Sality.aa [Kaspersky Lab]8
WORM_AUTORUN.RYU [Trend Micro]8
Mal/Generic-A [Sophos]7
W32.SillyDC [Symantec]7
W32/Autorun.worm.e [McAfee]7
W32/Sality.gen [McAfee]7
Worm.Win32.AutoRun.fmo [Kaspersky Lab]7
Worm.Win32.AutoRun.tej [Kaspersky Lab]7
W32/Spybot.worm.gen [McAfee]6
Win-Trojan/Hamweq.12800 [AhnLab]6
Win-Trojan/IRCBot.114688.B [AhnLab]6
Worm.AutoRun!sd6 [PC Tools]6
BackDoor-CKA [McAfee]5
W32/Sdbot.worm.gen.ay [McAfee]5
PE_SALITY.JER [Trend Micro]4
Trojan.Win32.Pakes.jzt [Kaspersky Lab]4
Trojan:Win32/Ircbrute [Microsoft]4
Win32/Autorun.worm.114176.B [AhnLab]4
Win32/IRCBot.worm.115200.V [AhnLab]4
Worm.Win32.AutoRun.gmf [Kaspersky Lab]4
Worm.Win32.AutoRun.qmd [Kaspersky Lab]4
WORM_AUTORUN.BKL [Trend Micro]4
PE_SALITY.EN-1 [Trend Micro]3
Suspicious.MH690 [Symantec]3
Troj/Autorun-WM [Sophos]3
Virus.Win32.Virut.ce [Kaspersky Lab]3
Virus:Win32/Virut.BM [Microsoft]3
W32.Virut.CF [Symantec]3
W32/Autorun.worm.n [McAfee]3
W32/AutoRun-OZ [Sophos]3
W32/AutoRun-WB [Sophos]3
Win-Trojan/Autorun.117248.B [AhnLab]3
Win-Trojan/Hamweq.12288 [AhnLab]3
Worm.Win32.AutoRun.ffu [Kaspersky Lab]3
Worm.Win32.AutoRun.spa [Kaspersky Lab]3
Worm.Win32.AutoRun.umg [Kaspersky Lab]3
Worm.Win32.AutoRun.uos [Kaspersky Lab]3
Worm:Win32/Autorun.MBS!corrupt [Microsoft]3
Backdoor.Graybird [Symantec]2
Backdoor.Graybird!sd6 [PC Tools]2
Hacktool.Flooder [Symantec]2
IRC-Worm.Win32.Small.am [Kaspersky Lab]2
IRC-Worm.Win32.Small.cc [Kaspersky Lab]2
PE_SALITY.EN [Trend Micro]2
Troj/Agent-JEF [Sophos]2
Trojan.Win32.Buzus.aosr [Kaspersky Lab]2
Trojan:Win32/Agent [Microsoft]2
W32.Virut.U [Symantec]2
W32/Autorun.worm!eu [McAfee]2
W32/AutoRun-JO [Sophos]2
W32/AutoRun-XZ [Sophos]2
W32/Sality.ao [McAfee]2
W32/Scribble-B [Sophos]2
W32/Vetor-A [Sophos]2
W32/Virut.gen [McAfee]2
W32/Virut.n.gen [McAfee]2
Win32/Autorun.worm.115712 [AhnLab]2
Win32/Autorun.worm.118272 [AhnLab]2
Win32/Autorun.worm.119808.B [AhnLab]2
Win32/Kashu.B [AhnLab]2
Win32/Virut.F [AhnLab]2
Win-Trojan/Agent.621568.B [AhnLab]2
Win-Trojan/Autorun.117248 [AhnLab]2
Win-Trojan/Autorun.119808.B [AhnLab]2
Win-Trojan/Buzus.18698 [AhnLab]2
Win-Trojan/Pakes.114176.C [AhnLab]2
Worm.AutoRun.oqu [PC Tools]2
Worm.AutoRun.qog [PC Tools]2
Worm.AutoRun.sbd [PC Tools]2
Worm.Win32.AutoRun.akfu [Kaspersky Lab]2
Worm.Win32.AutoRun.qye [Kaspersky Lab]2
Worm.Win32.AutoRun.rol [Kaspersky Lab]2
Worm.Win32.AutoRun.vhg [Kaspersky Lab]2
Worm.Win32.AutoRun.wfi [Kaspersky Lab]2
Worm.Win32.Hamweq.a [Kaspersky Lab]2
Backdoor.IRCBot!sd6 [PC Tools]1
Backdoor.Win32.Agent.adro [Kaspersky Lab]1
BackDoor-DOQ.gen.e [McAfee]1
DDoS-Leba [McAfee]1
Generic BackDoor.u [McAfee]1
IRC Trojan [Symantec]1
IRC-Worm.Win32.Small.u [Kaspersky Lab]1
Mal/Behav-227 [Sophos]1
New Malware.bj [McAfee]1

Worm.Win32.Hamweq [Ikarus] is known to be created as:
%Temp%\decrypted.exe
%Temp%\recycler\k-1-3542-4232123213-7676767-8888886\xv.exe
%Windir%\crypted.exe
%Windir%\winnt.exe
c:\config\s-1-5-21-1482476501-1644491937-682003330-1013\cfg.exe
c:\config\s-1-5-21-1482476501-1644491937-682003330-1013\usr.exe
c:\driver\files\driver.exe
c:\murkrow.exe
c:\recycle\d-0-060-0000000000-1111111-2222222\ryan.exe
c:\recycler\h-6-1-53-0976546321-090909032-8763-1337\zerx.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886\hn.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886\xv.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\devrgm.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\maq.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\ogard.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\wins32.exe
c:\restore\s-1-5-21-1482476501-1644491937-682003330-1013\rox.exe
c:\system\s-1-5-21-1482476501-1644491937-682003330-1013\sys.exe
c:\system\s-1-5-21-1482476501-1644491937-682003330-1013\usb.exe
Notes:
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.