GWGhost 2.1
(Trojan.Win32.GwGhost.20)

by Machine_GW

Compressed with ASPack

Released in December 2001

Made in China

more versions


Server:
c:\WINDOWS\SYSTEM\scanregw.exe 

size: 36.608 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "ScanRegistry" 
Old data: C:\WINDOWS\scanregw.exe /autorun 
New data: C:\WINDOWS\SYSTEM\SCANREGW.EXE /autorun 

MegaSecurity