Guangwai Girl 2.5 Alpha 3
(Backdoor.Win32.GWGirl.25.b)

by Guangwai

Compressed with ASPack

Released in February 2002

Made in China

more versions


Server:
dropped files:
c:\WINNT\system32\DXInput.dll  size: 20.480 bytes 
c:\WINNT\system32\SCANREGW.EXE size: 36.608 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ScanRegistry"
data: C:\WINNT\system32\SCANREGW.EXE /autorun
 
tested on win2000

MegaSecurity