China 1.1
(Backdoor.Win32.ChinDoor.11)

by ?

Written in Visual Basic

Released in July 2001

Made in China

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\Window.exe 

size: 88 KB

port: 8210 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "Window"
 
Added:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" 

MegaSecurity