RedGirl 2007 Build0122
(Backdoor.Win32.SdBot.ejw)
(Trojan-Spy.Win32.Agent.pi for Server)

by ?

Released in January 2007

Made in China




Server:
dropped files:
c:\WINDOWS\system32\RedGirl.dat    Size: 349,184 bytes 
c:\WINDOWS\system32\RedGirl.exe    Size: 393,900 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_REDGIRL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RedGirl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_REDGIRL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RedGirl




tested on Windows XP
March 22, 2007

MegaSecurity