Threat Search: 

ThreatExpert's Statistics for Worm.Win32.Neeris [Ikarus]:

Worm.Win32.Neeris [Ikarus] is also known as:
Threat AliasNumber of Incidents
Worm:Win32/Neeris.AN [Microsoft]19
Backdoor.Sdbot [Symantec]14
W32/SdBot-DKI [Sophos]11
W32.Spybot.Worm [Symantec]9
Win32/Autorun.worm.32256.D [AhnLab]9
Virus.Win32.Virut.ce [Kaspersky Lab]5
Generic.dx [McAfee]4
Mal/HckPk-A, W32/Virut-Gen [Sophos]4
Worm:Win32/Neeris.gen!C [Microsoft]4
Backdoor.Win32.IRCBot.jwy [Kaspersky Lab]3
PE_VIRUT.AT [Trend Micro]3
Suspicious.MH690 [Symantec]3
Virus.Win32.Virut.at [Kaspersky Lab]3
W32.IRCBot [Symantec]3
W32/Rbot-GXR [Sophos]3
W32/Virut.gen.a [McAfee]3
Win32.Virut.Gen.4 [PC Tools]3
Win32/Virut [AhnLab]3
Mal/HckPk-A, W32/Scribble-B [Sophos]2
W32/Scribble-A [Sophos]2
W32/Sdbot.worm [McAfee]2
W32/Virut.n [McAfee]2
Backdoor.IRCBot!sd6 [PC Tools]1
Backdoor.Win32.IRCBot.gxj [Kaspersky Lab]1
Backdoor:Win32/Numnom.A [Microsoft]1
Backdoor:Win32/Sdbot.BD [Microsoft]1
BackDoor-DOQ.gen.e [McAfee]1
Cryp_PESpin [Trend Micro]1
Mal/Behav-116, Mal/TinyDL-T, Mal/HckPk-A [Sophos]1
Mal/Generic-A [Sophos]1
Mal/HckPk-A, W32/Vetor-A [Sophos]1
Mal/TinyDL-T, Mal/Behav-024, Mal/Emogen-G, Mal/IRCBot-B, Mal/HckPk-A [Sophos]1
Mal/TinyDL-T, Mal/Behav-024, Mal/Emogen-G, Mal/IRCBot-B, Mal/SillyFDC-A, Mal/Behav-027, Mal/HckPk-A, Mal/Behav-010 [Sophos]1
Mal/TinyDL-T, Mal/Packer, Mal/SillyFDC-A [Sophos]1
Net-Worm.Kolab [PC Tools]1
Net-Worm.Win32.Kolab.bgr [Kaspersky Lab]1
Net-Worm.Win32.Kolab.bzd [Kaspersky Lab]1
Net-Worm.Win32.Kolab.cbk [Kaspersky Lab]1
Net-Worm.Win32.Kolab.ccn [Kaspersky Lab]1
Net-Worm.Win32.Kolab.efb [Kaspersky Lab]1
Packed.Generic.135 [Symantec]1
PE_VIRUT.ABY [Trend Micro]1
PE_VIRUT.D [Trend Micro]1
Troj/Buzinj-A [Sophos]1
Trojan.Agent!sd6 [PC Tools]1
Trojan.Donbot [Symantec]1
Trojan.Win32.Agent.bpfz [Kaspersky Lab]1
Trojan.Win32.Buzus.asqc [Kaspersky Lab]1
Trojan.Win32.Buzus.cepx [Kaspersky Lab]1
VirTool:Win32/DelfInject.gen!J [Microsoft]1
Virus.Win32.Virut.bl [Kaspersky Lab]1
W32.Virut.CF [Symantec]1
W32/Kolabc-G [Sophos]1
W32/Scribble-B [Sophos]1
W32/Spybot.worm!bx [McAfee]1
W32/Virut.gen [McAfee]1
W32/Virut.j [McAfee]1
W32/Virut.n.gen [McAfee]1
Win32.Virut.Gen [PC Tools]1
Win32/IRCBot.worm.variant [AhnLab]1
Win32/Kolab.worm.111616 [AhnLab]1
Win32/Kolab.worm.59904.C [AhnLab]1
Win32/Virut.E [AhnLab]1
Win32/Virut.Gen [AhnLab]1
Win-Trojan/Buzus.46074 [AhnLab]1
Worm.AutoRun.tet [PC Tools]1
Worm.RBot.Gen.16 [PC Tools]1
Worm.Win32.AutoRun.adkh [Kaspersky Lab]1
Worm.Win32.AutoRun.suc [Kaspersky Lab]1
Worm.Win32.AutoRun.unu [Kaspersky Lab]1
Worm.Win32.AutoRun.use [Kaspersky Lab]1
Worm.Win32.AutoRun.xjw [Kaspersky Lab]1

Worm.Win32.Neeris [Ikarus] is known to be created as:
%System%\csrsc.exe
%System%\iwsivs.exe
%Temp%\fsd442.exe
%Windir%\system\msddll.exe
%Windir%\system\ntlansec.exe
%Windir%\system\qwidh.exe
%Windir%\system\svchost.exe
%Windir%\system\svhost.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.