Threat Search: 

ThreatExpert's Statistics for Worm.Win32.AutoRun.gmf [Kaspersky Lab]:

Worm.Win32.AutoRun.gmf [Kaspersky Lab] is also known as:
Threat AliasNumber of Incidents
W32/Autoham-Fam [Sophos]9
Win-Trojan/Agent.13824.FE [AhnLab]7
Worm:Win32/Hamweq.A [Microsoft]7
W32.Ircbrute [Symantec]4
Worm.Hamweg.Gen [PC Tools]4
Worm.Win32.Hamweq [Ikarus]4
Backdoor.Trojan [Symantec]3
Win-Trojan/Hamweq.12288 [AhnLab]3
Generic.dx [McAfee]2
IRC-Worm.Win32.Small [Ikarus]2
Mal/Generic-A [Sophos]2
Mal/Krap-D [Sophos]2
Suspicious.MH690 [Symantec]2
Trojan:Win32/Ircbrute [Microsoft]2
Trojan-DDoS.Win32.Agent.bv [Ikarus]2
W32/Autorun.worm!eu [McAfee]2
Hacktool.Flooder [Symantec]1
Infostealer [Symantec]1
PE_PARITE.A [Trend Micro]1
Trojan-PSW.Generic [PC Tools]1
Virus:Win32/Parite.B [Microsoft]1
W32/Autorun.worm!bf [McAfee]1
W32/IRCbot.worm.gen [McAfee]1
W32/Parite-B [Sophos]1
W32/Pate.b [McAfee]1
W32/Quatoit [McAfee]1
Win32/Parite [AhnLab]1
Win32/Xema.worm.15227 [AhnLab]1
Win-Trojan/Agent.15227.C [AhnLab]1
Win-Trojan/Agent.15227.D [AhnLab]1
Worm:Win32/Hamweq.I [Microsoft]1
WORM_AUTORUN.RYU [Trend Micro]1

Worm.Win32.AutoRun.gmf [Kaspersky Lab] is known to be created as:
%Windir%\crypted.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.