W32/AutoRun-CU is a worm for the Windows platform.

W32/AutoRun-CU includes functionality to download, install and run new software.

When first run W32/AutoRun-CU copies itself to:


Root\qqvnet.exe
System\qqvnet.exe

and creates the following files:

Root\AutoRun.inf
System\DreamweaverDel.bat

The file qqvnet.exe is registered as a new system driver service named "qqvnet,", with a display name of "Chinavent online Chinaventonlin" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\qqvnet

More information can be found at this Sophos page.