GG Control Tool 1.2
(Backdoor.Win32.GGDoor.12)

by Pdm


Released in August 2005

Made in Poland


GG Control Tool v 1.2

What is GG Control Tool ??
GG Control Tool is a tool for computer remote control. It use gadu-gadu protocol (gadu-gadu is polish comunicator like icq etc).
This solution allow to work even on people who are behind NAT. If you want use this you should have instaled Gadu-Gadu comunicator.
This is necessarily to create new gg numbers. First number will be use by GG Control Tool, second will be your own number for use by Gadu-Gadu (client).

Does it work only in XP ??
All my programs was write in Windows XP SP1. I didn't test it in others system versions

How use this tool ??
You have to connect from some communicator for exemple: gadu-gadu (but also work with tlen and konnekt).
Next step is very easy. When GGControl Tool is connect to gadu-gadu server, you should type right command in comunicator window.

What it is able to do ?? Where I find this commands ??
Version 1.2

-Server Generator for specific gg number with mode
-Hiding
-Autostart
-Define ftp adres where will be send files from infected computer
-New appearance
Correct small errors
New small size: 284 KB

Commands:
help - help, shows all commands
exit - shutdown the server
magnesik on - turn on magnetic power
magnesik off - turn off magnetic power
monitor off - turn off monitor
monitor on - turn on monitor
info - information about infected computer
screen - screenshot send by gg
cmd on - turn on dos command line (after type this command type normally dos command) To show result press "z")
cmd off - turn off dos command line
ftp - put ditals about ftp adres, user and password
ftpsciezka - path from it should take files, default c:\
ftpkolejny - name of file, next GG Control Tool check if exist. If yes send to the server
download - download file with specific location
pasek on - turn on menu start
pasek off - turn off menu start
wiadomosc - draw a message on monitor
wiadomosc2 - window message
kolory - reverse colors in windows
rozdzielczosc - change resolution
uninstall - remove trojan horse

Pdm


Server:
dropped file:
c:\WINDOWS\system32\updReg.EXE
size: 291,559 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "UpdReg"
data: C:\WINDOWS\system32\updReg.EXE 



tested on Windows XP
September 14, 2005

MegaSecurity