Sophos

W32/Chinegan-A

Aliases
  • Backdoor.Win32.Agent.aly
  • Win32/AGbot
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 3 April 2007 00:03:43 (GMT)
Detected by All Sophos products

Action

More Information

W32/Chinegan-A is a worm for the Windows platform.

W32/Chinegan-A spreads to other network computers by exploiting Symantec (SYM06-010) and by copying itself to network shares protected by weak passwords.

W32/Chinegan-A includes the following functionality:

- Download and execute code from a remote server via HTTP
- File transfers using FTP
- Exploits VNC servers with weak or no passwords
- Automatically adds itself to Windows Firewall Policy

When first run W32/Chinegan-A copies itself to:

<Program Files>\Common Files\inst32\inst32.exe

and creates the following registry entries:

HKLM\SYSTEM\CurrentControlSet\Services\inst32

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INST32

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Program Files>\Common Files\inst32
inst32.exe
<Program Files>\Common Files\inst32\inst32.exe:*:Enabled:inst32

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer