Guangwai Girl 1.52b
(Backdoor.Win32.GWGirl.152 for Client)
(Backdoor.Win32.GWGirl.151 for Server)

by Guangwai

Compressed with ASPack

Released in October 2001

Made in China

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\DIAGCFG.EXE 

size: 99.840 bytes 

port: 6267 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Diagnostic Configuration" 
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" 

added:
c:\WINDOWS\APPLOG\DIAGCFG.LGC 


MegaSecurity