Threat Search: 

ThreatExpert's Statistics for W32/Autorun.worm.b [McAfee]:

W32/Autorun.worm.b [McAfee] is also known as:
Threat AliasNumber of Incidents
Troj/Qhost-O [Sophos]141
Trojan:Win32/Qhost.V [Microsoft]136
W32.SillyFDC [Symantec]56
not-a-virus:RiskTool.Win32.HideProc.c [Kaspersky Lab]44
Virus.Win32.AutoRun.ain [Kaspersky Lab]39
not-a-virus:AdWare.Win32.Agent.dyp [Kaspersky Lab]30
Virus.Win32.AutoRun.as [Kaspersky Lab]24
TROJ_QHOST.MM [Trend Micro]22
Adware.Agent!sd6 [PC Tools]18
not-a-virus:RiskTool.Win32.HideProc.c [Ikarus]16
Win-Trojan/Autorun.71168.B [AhnLab]14
Trojan.Win32.Small.xup [Kaspersky Lab]12
Trojan-Dropper.Agent!sd6 [PC Tools]7
Backdoor:Win32/Agent.EO [Microsoft]5
Mal/Generic-A [Sophos]5
Mal/SillyFDC-A [Sophos]5
Trojan.Dropper [Symantec]5
Trojan:Win32/Hider.gen [Microsoft]5
Trojan.Win32.Agent.aebe [Kaspersky Lab]4
Trojan-Downloader.Win32.VB.hqj [Kaspersky Lab]4
W32.SillyDC [Symantec]4
Worm.Win32.AutoRun.lmc [Kaspersky Lab]4
Trojan Horse [Symantec]3
Trojan-Downloader.Win32.VB.gja [Kaspersky Lab]3
Worm.Autorun!ct [PC Tools]3
Worm.Win32.AutoRun [Ikarus]3
Possible_Otorun7 [Trend Micro]2
Virus.Win32.Downloader.ALQ [Ikarus]2
W32.Babelloh [Symantec]2
W32/AutoRun-GW [Sophos]2
W32/SillyFD-T [Sophos]2
Win-Trojan/Autorun.36864.J [AhnLab]2
Worm.Win32.AutoRun.any [Kaspersky Lab]2
Worm.Win32.AutoRun.cd [Kaspersky Lab]2
Worm.Win32.AutoRun.dhk [Kaspersky Lab]2
Dropper/Meredrop.88440 [AhnLab]1
not-a-virus:Server-Proxy.Win32.CCProxy.63 [Kaspersky Lab]1
Trojan.Crypt.NSPM [Ikarus]1
Trojan.VB!sd5 [PC Tools]1
Trojan.Win32.Agent [Ikarus]1
Trojan.Win32.Agent.byje [Kaspersky Lab]1
Trojan.Win32.Agent2.gnq [Kaspersky Lab]1
Trojan.Win32.FlyStudio.bz [Kaspersky Lab]1
Trojan.Win32.VB.axp [Kaspersky Lab]1
Trojan:Win32/Comronki!rts [Microsoft]1
Trojan-Downloader.Win32.VB.hfn [Kaspersky Lab]1
Trojan-Downloader.Win32.VB.hsx [Kaspersky Lab]1
Trojan-Dropper.Win32.Agent.yhq [Kaspersky Lab]1
Trojan-PSW.Win32.QQPass.aom [Kaspersky Lab]1
Trojan-PWS.Win32.QQPass [Ikarus]1
Virus.Win32.AutoRun.as [Ikarus]1
W32.Gammima [Symantec]1
W32/AutoRun-AZ [Sophos]1
W32/Autorun-KR, Mal/Behav-009 [Sophos]1
Win-Trojan/Autorun.49152.N [AhnLab]1
Win-Trojan/Autorun.77824.I [AhnLab]1
Win-Trojan/Autorun.89088 [AhnLab]1
Worm.AutoRun.AEC [PC Tools]1
Worm.Win32.AutoRun.emn [Kaspersky Lab]1
Worm.Win32.AutoRun.llx [Kaspersky Lab]1
Worm.Win32.AutoRun.pa [Kaspersky Lab]1
Worm.Win32.Fujack [Ikarus]1
WORM_AUTORUN.BSU [Trend Micro]1
WORM_VB.EAJ [Trend Micro]1

W32/Autorun.worm.b [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China97
Taiwan7

W32/Autorun.worm.b [McAfee] is known to be created as:
%FontsDir%\fonts.exe
%FontsDir%\lcsmssy.exe
%FontsDir%\smcw.exe
%FontsDir%\smvs.exe
%FontsDir%\uows.exe
%FontsDir%\wyxp.exe
%FontsDir%\yuower.exe
%FontsDir%\yxowr.exe
%System%\isass.exe
%System%\war.exe
%Temp%\kafan virlist 2009.04.02\090402-a-38.exe
%Windir%\help\smccpi.exe
%Windir%\help\smcuu.exe
%Windir%\scw.exe
Notes:
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.