Glacier ROSE
(Backdoor.Win32.G_Door.b)

by Y2KZERO

Compressed with ASPack

Released in June 2002

Made in China

more versions


Client:
port: 7718 TCP



Servers:
c:\WINDOWS\SYSTEM\Kernel32.exe 
c:\WINDOWS\SYSTEM\Sysexplr.exe 

size: 287.744 bytes

port: 7626 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "(Default)" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "(Default)" 
HKEY_CLASSES_ROOT\txtfile\shell\open\command "(Default)" 

added:
c:\WINDOWS\TEMP\Psw.tmp 

MegaSecurity