Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | May 2007 (4.17) |
| Protection available since | 3 April 2007 00:03:43 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Chinegan-A is a worm for the Windows platform.
W32/Chinegan-A spreads to other network computers by exploiting Symantec (SYM06-010) and by copying itself to network shares protected by weak passwords.
W32/Chinegan-A includes the following functionality:
- Download and execute code from a remote server via HTTP
- File transfers using FTP
- Exploits VNC servers with weak or no passwords
- Automatically adds itself to Windows Firewall Policy
When first run W32/Chinegan-A copies itself to:
<Program Files>\Common Files\inst32\inst32.exe
and creates the following registry entries:
HKLM\SYSTEM\CurrentControlSet\Services\inst32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INST32
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Program Files>\Common Files\inst32
inst32.exe
<Program Files>\Common Files\inst32\inst32.exe:*:Enabled:inst32
