Threat Search: 

ThreatExpert's Statistics for W32/Autorun.worm.c [McAfee]:

W32/Autorun.worm.c [McAfee] is also known as:
Threat AliasNumber of Incidents
Mal/Generic-A [Sophos]16
W32.SillyFDC [Symantec]16
W32.SillyDC [Symantec]8
Worm.SdBot.Gen.26 [PC Tools]7
Worm.Win32.AutoIt [Ikarus]7
Worm.Win32.AutoRun.mvi [Kaspersky Lab]6
Trojan Horse [Symantec]5
Worm.Win32.AutoRun [Ikarus]5
Worm.Win32.AutoIt.ar [Kaspersky Lab]4
Worm.Win32.AutoRun.chz [Kaspersky Lab]4
Worm.Win32.Small.z [Kaspersky Lab]4
Worm:Win32/Autorun.BZ [Microsoft]4
Worm:Win32/Autorun.CQ [Microsoft]4
WORM_AUTORUN.BIK [Trend Micro]4
Backdoor.Trojan [Symantec]3
Downloader [Symantec]3
Worm.AutoRun!sd5 [PC Tools]3
Mal/Autorun-F [Sophos]2
Troj/Agent-KNF [Sophos]2
Trojan.Panddos [Symantec]2
Trojan.Peed [Ikarus]2
Trojan.Win32.AgentBypass [Ikarus]2
Trojan-PWS.Win32.QQPass [Ikarus]2
W32.Imaut [Symantec]2
Win32/Autorun.worm.434353 [AhnLab]2
Worm.AutoIt [PC Tools]2
Worm.AutoIt!sd6 [PC Tools]2
Worm.Win32.AutoRun.dq [Kaspersky Lab]2
Worm:Win32/Autorun.MBS [Microsoft]2
Worm:Win32/Emold.gen!D [Microsoft]2
Backdoor.Graybird [Symantec]1
Backdoor.Win32.Agent.amb [Kaspersky Lab]1
Backdoor.Win32.Agent.ima [Kaspersky Lab]1
Backdoor.Win32.Httpbot.xc [Kaspersky Lab]1
Backdoor.Win32.Hupigon.ednz [Kaspersky Lab]1
Backdoor.Win32.IRCBot.nav [Kaspersky Lab]1
Backdoor:Win32/Agent.ADC [Microsoft]1
Backdoor:Win32/FlyAgent.F [Microsoft]1
Backdoor:Win32/IRCbot.DP [Microsoft]1
Bloodhound.Unknown [Symantec]1
Downloader.Generic [PC Tools]1
Dropper/Flystud.1407351 [AhnLab]1
Dropper/MulDrop.3426506 [AhnLab]1
IM-Worm.Win32.Agent [Ikarus]1
IM-Worm.Win32.Agent.md [Kaspersky Lab]1
IRC-Worm.Win32.Delf.q [Kaspersky Lab]1
Mal/Airworm-A [Sophos]1
Mal/Behav-156, Mal/Behav-043, Mal/Emogen-E, Mal/Packer [Sophos]1
Mal/Dropper-Q [Sophos]1
Mal/EncPk-AP, Mal/EncPk-BL [Sophos]1
Mal/EncPk-GF [Sophos]1
Mal/Generic-E [Sophos]1
Mal/TinyDL-T, Mal/Packer, Mal/Behav-024 [Sophos]1
Net-Worm.SillyFDC [PC Tools]1
Net-Worm.Win32.Mytob.rd [Kaspersky Lab]1
Net-Worm.Win32.Piloyd.m [Kaspersky Lab]1
not-a-virus:Monitor.Win32.ActualSpy.27 [Kaspersky Lab]1
Suspicious.MH690 [Symantec]1
TROJ_AGENT.UPZ [Trend Micro]1
TROJ_BUZUS.BL [Trend Micro]1
TROJ_DROPPER.NAW [Trend Micro]1
TROJ_SMALL.KNM [Trend Micro]1
Trojan.Autoit [Ikarus]1
Trojan.Buzus.IU [PC Tools]1
Trojan.Injecter.BV [PC Tools]1
Trojan.IRCBot [PC Tools]1
Trojan.Lineage.Gen!Pac.3 [PC Tools]1
Trojan.Shutdowner!sd6 [PC Tools]1
Trojan.Vaklik!sd6 [PC Tools]1
Trojan.VB.GKB [PC Tools]1
Trojan.Win32.Autoit.ci [Kaspersky Lab]1
Trojan.Win32.Buzus [Ikarus]1
Trojan.Win32.Buzus.gtl [Kaspersky Lab]1
Trojan.Win32.Delf.kba [Kaspersky Lab]1
Trojan.Win32.Shutdowner [Ikarus]1
Trojan.Win32.Shutdowner.bpq [Kaspersky Lab]1
Trojan.Win32.VB.bgo [Kaspersky Lab]1
Trojan:Win32/Agent.AHC [Microsoft]1
Trojan:Win32/Ircbrute [Microsoft]1
Trojan:Win32/ProcInject.B [Microsoft]1
Trojan-Downloader.Small!sd6 [PC Tools]1
Trojan-Downloader.Win32.Small.eef [Kaspersky Lab]1
Trojan-Downloader.Win32.VB.hkn [Kaspersky Lab]1
Trojan-Dropper.Agent!sd6 [PC Tools]1
Trojan-Dropper.Delf [Ikarus]1
Trojan-Dropper.Flystud!sd6 [PC Tools]1
Trojan-Dropper.Win32.Agent.agyv [Kaspersky Lab]1
Trojan-Dropper.Win32.Flystud.rg [Kaspersky Lab]1
Trojan-Spy.Win32.Agent.bbg [Ikarus]1
TSPY_ONLINEG.GKT [Trend Micro]1
Virus.Win32.AutoRun.abt [Kaspersky Lab]1
Virus.Win32.AutoRun.zw [Ikarus]1
Virus.Win32.Virut.q [Kaspersky Lab]1
W32.Fujacks!gen [Symantec]1
W32.IRCBot [Symantec]1
W32.Small.gen [Symantec]1
W32.Whybo [Symantec]1
W32.Whybo.Z [Symantec]1
W32/AutoRun-ABK [Sophos]1
W32/Autorun-AJN [Sophos]1

W32/Autorun.worm.c [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
China6
United Kingdom6
Iran3
Russian Federation1
Slovakia1
Slovenia1

W32/Autorun.worm.c [McAfee] is known to be created as:
%AppData%\alna.scr
%AppData%\lsass.exe
%AppData%\windowslive.exe
%CommonAppData%\dllcache32.exe
%CommonFavorites%\favorites.exe
%CommonPrograms%\startup\explorer.exe
%CommonPrograms%\startup\lsass.exe
%Favorites%\links\links.exe
%ProgramFiles%\common files\designer\designer.exe
%ProgramFiles%\common files\mssoap\binaries\binaries.exe
%ProgramFiles%\common files\mssoap\mssoap.exe
%ProgramFiles%\common files\odbc\odbc.exe
%ProgramFiles%\common files\services\services.exe
%ProgramFiles%\common files\speechengines\microsoft\tts\tts.exe
%ProgramFiles%\common files\speechengines\speechengines.exe
%ProgramFiles%\common files\system\ado\ado.exe
%ProgramFiles%\common files\system\msadc\msadc.exe
%ProgramFiles%\common files\system\system.exe
%ProgramFiles%\common files\wqkas.exe
%ProgramFiles%\explorer.exe
%ProgramFiles%\internet explorer\connection wizard\aanan.exe
%ProgramFiles%\internet explorer\mui\0409\0409.exe
%ProgramFiles%\internet explorer\mui\mui.exe
%ProgramFiles%\internet explorer\signup\signup.exe
%ProgramFiles%\messenger\messenger.exe
%ProgramFiles%\microsoft common\svchost.exe
%ProgramFiles%\microsoft frontpage\version3.0\bin\bin.exe
%ProgramFiles%\microsoft frontpage\version3.0\version3.0.exe
%ProgramFiles%\msn gaming zone\windows\windows.exe
%ProgramFiles%\msn\msn.exe
%ProgramFiles%\msn\msncorefiles\install\install.exe
%ProgramFiles%\msn\msncorefiles\msncorefiles.exe
%ProgramFiles%\msn\msncorefiles\oobe\oobe.exe
%ProgramFiles%\msn\msnia\msnia.exe
%ProgramFiles%\msn\msninstaller\msninstaller.exe
%ProgramFiles%\netmeeting\netmeeting.exe
%ProgramFiles%\rtlcpli.exe
%ProgramFiles%\web publish\logfiles\logfiles.exe
%ProgramFiles%\windows media player\aaaaa.exe
%Programs%\startup\solari.exe
%System%\1cb5ad\aa2e5e.exe
%System%\directx\svchost.exe
%System%\dllcache\nnnnn.exe
%System%\dllcache32.exe
%System%\drivers\spoclsv.exe
%System%\drivers\svchost.exe
%System%\explorcr.exe
%System%\ime\ywvzw.exe
%System%\k4hostelsvc.exe
%System%\kxvo.exe
%System%\msdumprep.exe
%System%\regsvr.exe
%System%\rising.exe
%System%\svch0st.exe
%System%\xp-c300c3ac.exe
%System%\zczxcx.exe
%Temp%\_systemupdate.exe
%Temp%\latest.exe
%Temp%\msdtr.exe
%Windir%\addins\ceeya.exe
%Windir%\auto.exe
%Windir%\backup\explorer.exe
%Windir%\keeper.exe
%Windir%\killer.exe
%Windir%\regsvr.exe
%Windir%\smss.exe
%Windir%\system\guiao.exe
%Windir%\system\msdumprep.exe
%Windir%\systemupdate.exe
%Windir%\systom32\svchost.exe
c:\ab.exe
c:\ab\bas.exe
c:\al.exe
c:\al\li.exe
c:\babylon.exe
c:\babylon\picture.exe
c:\barname.exe
c:\barname\download.exe
c:\computer.exe
c:\computer\cpu.exe
c:\computers.exe
c:\computers\motherboard.exe
c:\country.exe
c:\country\al.exe
c:\cpu.exe
c:\cpu\jeneral.exe
c:\deh.exe
c:\deh\downloads.exe
c:\delphi.exe
c:\delphi\country.exe
c:\download.exe
c:\downloads.exe
c:\explorer.exe
c:\film.exe
c:\film\good.exe
c:\films.exe
c:\films\otvali.exe
c:\good.exe
c:\good\project.exe
c:\home.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %Favorites% is a variable that refers to the file system directory that serves as a common repository for the user's favorite items. A typical path is C:\Documents and Settings\[UserName]\Favorites.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.