W32/Autorun.cb is a worm that spreads by copying itself to other drives, and also downloads additional malware.

Upon execution, this worm copies itself into the %Temp% folder.

%Temp%\WinUpdter.exe


The worm then launches a new instance of svchost.exe, and injects itself into this process.

It then connects to the following sites, probably to download additional malware.

  • 61.220.112.238
  • 202.142.180.165
  • 203.118.40.36
  • at the time of writing this description, the above websites were unresponsive.

    More information can be found at this McAfee page.