W32/AutoRun-CU is a worm for the Windows platform.
W32/AutoRun-CU includes functionality to download, install and run new software.
When first run W32/AutoRun-CU copies itself to:
Root\qqvnet.exe
System\qqvnet.exe
and creates the following files:
Root\AutoRun.inf
System\DreamweaverDel.bat
The file qqvnet.exe is registered as a new system driver service named "qqvnet,", with a display name of "Chinavent online Chinaventonlin" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\qqvnet
More information can be found at this Sophos page.
Loading Comments...