Threat Search: 

ThreatExpert's Statistics for Worm.Win32.AutoRun [Ikarus]:

Worm.Win32.AutoRun [Ikarus] is also known as:
Threat AliasNumber of Incidents
Generic!atr [McAfee]20,084
INF.Autorun.Gen [PC Tools]19,722
Downloader.inf [McAfee]18,000
Trojan.Noupdate.B [Symantec]14,800
Generic component [McAfee]12,810
W32/Hakaglan.inf [McAfee]8,877
Trojan Horse [Symantec]4,907
Worm.Win32.AutoRun.dck [Kaspersky Lab]4,650
W32/Xorer-A [Sophos]4,450
Worm.Win32.AutoRun.ezt [Kaspersky Lab]4,308
Virus.Win32.AutoRun.mg [Kaspersky Lab]4,095
Generic Rootkit.g [McAfee]3,953
Worm.Autorun.BJ [PC Tools]3,843
HackTool:WinNT/Tcpz.A [Microsoft]3,540
Hacktool.Rootkit [Symantec]3,517
Virus:Win32/Xorer.D!inf [Microsoft]3,300
Win-Trojan/Rootkit.11656 [AhnLab]3,068
Worm:Win32/Autorun!inf [Microsoft]2,868
Worm.AutoRun!sd6 [PC Tools]2,467
Trojan.Win32.AutoRun.a [Kaspersky Lab]2,278
Mal/AutoInf-A [Sophos]2,269
TextImage/Autorun [AhnLab]2,192
W32/Rbot-GXM [Sophos]2,065
Worm.Win32.AutoRun.nuu [Kaspersky Lab]1,739
W32/Autorun-KO [Sophos]1,628
W32/Autorun-KH [Sophos]1,544
Worm.Win32.AutoRun.blw [Kaspersky Lab]1,530
Rootkit.Agent [PC Tools]1,475
W32/SillyFDC-AU [Sophos]1,411
Worm.Win32.AutoRun.aaz [Kaspersky Lab]1,368
Trojan:Win32/Alureon!inf [Microsoft]1,258
W32/Autorun-AMP [Sophos]1,003
HackTool.Win32.Tcpz [Ikarus]944
Virus.Win32.AutoRun.abt [Kaspersky Lab]931
W32/AutoRun-KU [Sophos]900
Worm.Win32.AutoRun.ubh [Kaspersky Lab]817
Worm.AutoRun.AN [PC Tools]812
Virus.Win32.AutoRun.uz [Kaspersky Lab]804
W32.SillyDC [Symantec]780
Trojan.Win32.AutoRun [Ikarus]775
Worm.Win32.AutoRun.ekr [Kaspersky Lab]736
W32.SillyFDC [Symantec]688
Worm.Win32.AutoRun.dkp [Kaspersky Lab]667
Worm.Win32.AutoRun.rja [Kaspersky Lab]667
Mal/Generic-A [Sophos]657
HackTool:Win32/Tcpz.A [Microsoft]649
Infostealer.Gampass [Symantec]576
Generic.dx [McAfee]543
Mal/AutoInf-A, Mal/AutoInf-B [Sophos]527
Downloader [Symantec]501
W32/Autorun.worm.gen [McAfee]501
W32/Imaut-A [Sophos]495
W32/Rbot-GWP [Sophos]494
Worm:Win32/Taterf!inf [Microsoft]469
Worm.Win32.AutoRun.aox [Kaspersky Lab]434
W32/SillyFD-G [Sophos]385
W32/SillyFDC-BA [Sophos]378
Worm.Win32.AutoRun.ek [Kaspersky Lab]339
Virus.Win32.AutoRun.dq [Kaspersky Lab]297
Worm.Win32.AutoRun.nvc [Kaspersky Lab]296
Worm.Win32.AutoRun.vnq [Kaspersky Lab]198
Win32.AutoRun.H [PC Tools]195
Worm.Win32.AutoRun.aka [Kaspersky Lab]192
Trojan-GameThief.Win32.OnLineGames.eqs [Kaspersky Lab]182
W32/AutoRun-CR [Sophos]182
Worm.Win32.AutoRun.bma [Kaspersky Lab]180
Trojan-Proxy.Agent [PC Tools]177
Mal/AutoInf-B, Mal/AutoInf-A [Sophos]174
Worm.Win32.AutoRun.aqm [Kaspersky Lab]162
Worm.Win32.AutoRun.cns [Kaspersky Lab]156
Worm.Win32.AutoRun.wun [Kaspersky Lab]156
Worm.Autorun!ct [PC Tools]155
Worm.Win32.AutoRun.p [Kaspersky Lab]155
W32/Autorun-AEI [Sophos]152
Worm.Win32.AutoRun.eae [Kaspersky Lab]147
Virus.Win32.AutoRun.mg [Ikarus]140
Trojan.Autorun!ct [PC Tools]133
Trojan.AutorunINF [Ikarus]120
Win32/Autorun.worm.17408.C [AhnLab]118
Worm.Win32.AutoRun.lxz [Kaspersky Lab]117
Backdoor.Tidserv [Symantec]111
W32/Sdbot-DIQ [Sophos]104
Trojan:Win32/Chiviper.B [Microsoft]102
Virus.Worm.Win32.AutoRun.rja [Ikarus]92
Trojan-PSW.Win32.OnLineGames.eqs [Kaspersky Lab]91
Worm.Win32.AutoRun.gss [Kaspersky Lab]91
Win-Trojan/Agent.25600.RU [AhnLab]90
W32/Autorun.worm.bx [McAfee]83
Worm.Win32.AutoRun.ump [Kaspersky Lab]81
Mal/Dropper-Q [Sophos]80
W32/Cekar-E [Sophos]80
W32/Sobarbo.dll [McAfee]80
Worm.Win32.AutoRun.dzn [Kaspersky Lab]80
Worm:Win32/Autorun.GO!inf [Microsoft]78
W32/Yahlov-A [Sophos]73
Hacktool.Rootkit!sd6 [PC Tools]72
Trojan-Downloader.Flux.FM [PC Tools]72
W32.Gammima.AG [Symantec]72
PWS-Gamania.gen.a [McAfee]69
Trojan.Lineage.Gen!Pac.3 [PC Tools]69

Worm.Win32.AutoRun [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
China232
United Kingdom94
Russian Federation74
Spain19
Belgium4
Canada4
Thailand4
Iran3
Republic of Korea3
Saudi Arabia3
Sweden3
Taiwan3
Germany2
Indonesia2
Japan2
Netherlands2
Brazil1
France1
Mexico1
Poland1
Serbia and Montenegro1
Slovenia1
Syria1
Ukraine1

Worm.Win32.AutoRun [Ikarus] is known to be created as:
%AllUsersProfile%\aeazmcifi.exe
%AllUsersProfile%\desktop.exe
%AllUsersProfile%\documents.exe
%AllUsersProfile%\favorites.exe
%AllUsersProfile%\smss.exe
%AppData%\control.exe
%AppData%\microsoft\cd burning\mp3.exe
%AppData%\microsoft\cd burning\protector.exe
%AppData%\microsoft\svchost.exe
%AppData%\microsoft\windata\__arestra__best.exe
%AppData%\microsoft\winlogom.exe
%AppData%\servicehost.exe
%AppData%\sysdate32.exe
%CommonAppData%\aoety.exe
%CommonAppData%\axqhsdo.exe
%CommonAppData%\bfztua.exe
%CommonAppData%\bgzpbuhp.exe
%CommonAppData%\bnavf.exe
%CommonAppData%\brnor.exe
%CommonAppData%\bwdqd.exe
%CommonAppData%\byuuz.exe
%CommonAppData%\cqwwuxmep.exe
%CommonAppData%\crmrwhsqz.exe
%CommonAppData%\cybbwa.exe
%CommonAppData%\dbexawc.exe
%CommonAppData%\dcjluxrpb.exe
%CommonAppData%\djnbedat.exe
%CommonAppData%\djylzgema.exe
%CommonAppData%\dlvzoi.exe
%CommonAppData%\eelrcfmpk.exe
%CommonAppData%\einxckjra.exe
%CommonAppData%\ejuwuiqy.exe
%CommonAppData%\ekewldck.exe
%CommonAppData%\enaxltcgb.exe
%CommonAppData%\etpxdeiqs.exe
%CommonAppData%\fhuzpxbuf.exe
%CommonAppData%\fkpyas.exe
%CommonAppData%\fnqueubd.exe
%CommonAppData%\fofamn.exe
%CommonAppData%\fvaaa.exe
%CommonAppData%\fxrjr.exe
%CommonAppData%\fxrjrer.exe
%CommonAppData%\gwiublz.exe
%CommonAppData%\halts.exe
%CommonAppData%\hxwfn.exe
%CommonAppData%\hzmtowovo.exe
%CommonAppData%\iiuxa.exe
%CommonAppData%\ikutjpv.exe
%CommonAppData%\imxkdymge.exe
%CommonAppData%\ipnrup.exe
%CommonAppData%\iwrdxxcvu.exe
%CommonAppData%\ixcsuw.exe
%CommonAppData%\iyjmkw.exe
%CommonAppData%\jqkicm.exe
%CommonAppData%\jqkicmedj.exe
%CommonAppData%\jslweapg.exe
%CommonAppData%\jslweapgh.exe
%CommonAppData%\kimslppi.exe
%CommonAppData%\knzkhzx.exe
%CommonAppData%\lambda\dirlock.exe
%CommonAppData%\lxyffeihb.exe
%CommonAppData%\mchujuq.exe
%CommonAppData%\microsoft\aopcute.exe
%CommonAppData%\microsoft\bgkbp.exe
%CommonAppData%\microsoft\bpbalns.exe
%CommonAppData%\microsoft\brkyur.exe
%CommonAppData%\microsoft\cjxcz.exe
%CommonAppData%\microsoft\clkxdq.exe
%CommonAppData%\microsoft\cqsflkxk.exe
%CommonAppData%\microsoft\crypto\bgaqaavsz.exe
%CommonAppData%\microsoft\crypto\bquapskyp.exe
%CommonAppData%\microsoft\crypto\cldfn.exe
%CommonAppData%\microsoft\crypto\coqic.exe
%CommonAppData%\microsoft\crypto\cxfwgwd.exe
%CommonAppData%\microsoft\crypto\dss\aktgvob.exe
%CommonAppData%\microsoft\crypto\dss\apusct.exe
%CommonAppData%\microsoft\crypto\dss\bthpnthxs.exe
%CommonAppData%\microsoft\crypto\dss\bvnlaxl.exe
%CommonAppData%\microsoft\crypto\dss\cldfnt.exe
%CommonAppData%\microsoft\crypto\dss\drrdctgay.exe
%CommonAppData%\microsoft\crypto\dss\ephfcvlbj.exe
%CommonAppData%\microsoft\crypto\dss\ewqysj.exe
%CommonAppData%\microsoft\crypto\dss\eyvjoh.exe
%CommonAppData%\microsoft\crypto\dss\frerc.exe
%CommonAppData%\microsoft\crypto\dss\fwumj.exe
%CommonAppData%\microsoft\crypto\dss\hevioa.exe
%CommonAppData%\microsoft\crypto\dss\hxmexjz.exe
%CommonAppData%\microsoft\crypto\dss\ijzcjx.exe
%CommonAppData%\microsoft\crypto\dss\iljlo.exe
%CommonAppData%\microsoft\crypto\dss\jmzphtwvu.exe
%CommonAppData%\microsoft\crypto\dss\klmxyo.exe
%CommonAppData%\microsoft\crypto\dss\lonqrmxd.exe
%CommonAppData%\microsoft\crypto\dss\lwzjkrhz.exe
%CommonAppData%\microsoft\crypto\dss\lwzjkrhzl.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\aopcu.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\bebmvk.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\bpcbkuz.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\btnonyf.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\cbtmaup.exe
%CommonAppData%\microsoft\crypto\dss\machinekeys\cdmtfjohp.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.