TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
ALS_CHENGWA.A
Overview

Malware type: Others

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This malware is an AutoLISP script file that may be downloaded unknowingly by a user when visiting malicious Web site(s).

It is executed once an AutoCAD drawing file (.DWG) is opened.

Upon execution it attempts to undefine certain commands. After replacing the said commands with dummy commands, this malware then redefines them.

It then displays a message box with possibly Chinese scripts as text.

It also connects to a certain URL. It then searches for a certain file in the current working folder then replaces the said file with its own copy.

It also creates registry key(s)/entry(ies).

For additional information about this threat, see:
Solution
Technical Details

Description created: Jul. 18, 2008 12:24:12 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.