Threat Database Viruses Virus:Win32/Virut.gen!AO

Virus:Win32/Virut.gen!AO

By LoneStar in Viruses

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1,605
First Seen: May 14, 2013
Last Seen: February 5, 2026
OS(es) Affected: Windows

Virus:Win32/Virut.gen!AO is a virus, which enables cybercriminals to obtain access to a compromised PC. Virus:Win32/Virut.gen!AO drops and executes malevolent files and resricts a target computer user from visiting security-related websites. Virus:Win32/Virut.gen!AO is distributed through corrupted networks and removable drives such as USB sticks, floppy disks or flash card readers. Virus:Win32/Virut.gen!AO searches for all the removable drives on the corrupted PC from drive D:\ to Z:\. When Virus:Win32/Virut.gen!AO is finds a removable drive, it installs a copy of itself with a randomly created filename. Virus:Win32/Virut.gen!AO can destroy some corrupted files and does not allow to repair them. Virus:Win32/Virut.gen!AO blocks programs from operating appropriately or makes them crash when executed. Virus:Win32/Virut.gen!AO is a polymorphic file infector, which embeds a malevolent code into every .EXE and .SCR file that it finds on the attacked PC. While being executed, Virus:Win32/Virut.gen!AO embeds a malevolent code into the 'WINLOGON.exe' process. Virus:Win32/Virut.gen!AO creates the registry entry so that the virus is embedded on the authorized program list of the firewall.

File System Details

Virus:Win32/Virut.gen!AO may create the following file(s):
# File Name Detections
1. VPyKrBDo.exe
2. HDWXPx64.exe
3. AjsCEJmF.exe
4. XjKBISPV.exe

Registry Details

Virus:Win32/Virut.gen!AO may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "\??\" "\??\:*:enabled:@shell32.dll,-1"

Analysis Report

General information

Family Name: Virus.Virut.I
Signature status: No Signature

Known Samples

MD5: aef1c7de41ea7fb7cd044696c2b0e6d1
SHA1: fc2bcbbb3d5b746258acd85836b8273e214d212d
SHA256: 6BA71FD1D011E3A7CFE3FC881F883F64384C24AB4A82BE1159F17DD9CC03A738
File Size: 444.42 KB, 444416 bytes
MD5: 93869e5ea7d1ef68326ceb1b457d1a63
SHA1: 473f0d0f81a71900589aa37cd4a30e8c1526b572
SHA256: E34CE0A4812F5D082E97D53E43B34615D402BFDD3270123528400C1A332E6D28
File Size: 109.57 KB, 109568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Change Computer Performance Settings
File Version 6.1.7600.16385 (win7_rtm.090713-1255)
Internal Name SystemPropertiesPerformance
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename SystemPropertiesPerformance.EXE
Product Name Microsoft® Windows® Operating System
Product Version 6.1.7600.16385

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 30
Potentially Malicious Blocks: 10
Whitelisted Blocks: 13
Unknown Blocks: 7

Visual Map

0 0 0 0 0 2 3 1 0 0 0 0 x ? ? x x x ? ? x ? ? 0 x x x ? x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\fc2bcbbb3d5b746258acd85836b8273e214d212d_0000444416 c:\users\user\downloads\fc2bcbbb3d5b746258acd85836b8273e214d212d_0000444416:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\##10.200.31.10#amas::_labelfromdesktopini RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Trending

Most Viewed

Loading...