GOP 1.0
(Trojan-PSW.Win32.GOPtrojan.101)
(Trojan-PSW.Win32.GOPtrojan for gHookDll.dll)

by ?

Compressed with UPX

Released in January 2001

Made in China

more versions


Server:
dropped files:
c:\WINDOWS\system32\gHookDll.dll    Size: 57,344 bytes 
c:\WINDOWS\system32\sysexhook.exe   Size: 42,115 bytes  

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsAgent"
data: c:\windows\system32\sysexhook.exe 



tested on Windows XP
June 25, 2005

MegaSecurity