Home Malware Programs Remote Administration Tools Guangwaigirl

Guangwaigirl

Posted: March 28, 2006

The author of this RAT virus is a Chinese Hacker called Guangwai. Several variants appeared from August 2001 to February 2004. The application is compressed with ASPack. A Remote Administration Tool is a special kind of hacker malware, used for remote access and control of other people's PCs. The attacker infects the PC via the e-mail or File and Print Sharing. A "server" allows him to connect via a "client" on his own machine. The functions of a RAT may vary, depending on the needs of the hacker. Some RATs can't really harm your PC and the only purpose they were made for is hooliganism. But some versions can steal vital information, remove files and even crash your computer. The infection peaked in the United States and Russian Federation.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 -í--.exe
    2 backdoor.gwgirl.25.exe
    3 configdwform.dfm
    4 dwform.pas
    5 events.txt
    6 gdufs.exe
    7 guangwaigirl1.0.b.exe
    8 gwg-server.exe
    9 gwg.dpr
    10 gwg.exe
    11 gwghost.exe
    12 gwgirl.exe
    13 ipmlform.dfm
    14 ipmlform.pas
    15 readit.txt
    16 readme.txt
    17 readme_b5.txt
    18 readme_gb.txt
    19 setghost.exe
    20 strform.dfm
    21 strform.pas
    22 unit1.dfm
    23 unit1.pas
    24 unit2.dfm
    25 unit2.pas
Loading...