Home Malware Programs Trojans Trojan:Win32/Glod.A

Trojan:Win32/Glod.A

Posted: June 19, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 14
First Seen: June 19, 2013
Last Seen: February 9, 2024
OS(es) Affected: Windows

Trojan:Win32/Glod.A is a Trojan, which monitors what keys a target PC user presses and transfers this information to a remote attacker. Trojan:Win32/Glod.A can gain remote access to the victim's user names and passwords. Trojan:Win32/Glod.A may be installed on the affected computer by posing as a legal application, or by other malware infections.Trojan:Win32/Glod.A may steal the attacked computer user's confidential information, involving your usernames and passwords. While being installed on the infected computer system, Trojan:Win32/Glod.A makes system changes by dropping harmful files and making registry modifications. Trojan:Win32/Glod.A may use social engineering to persuade the affected computer user to install it on the infected computer system. Trojan:Win32/Glod.A can pose as a screen saver file 'image.scr', or it may also be downloaded by other malware threats. When executed, Trojan:Win32/Glod.A monitors and logs keystrokes and active windows as the victimized PC user uses the infected computer. Trojan:Win32/Glod.A then transmits this information to a remote attacker at the certain URL.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERPROFILE%\Common Files\openv.exe File name: %ALLUSERPROFILE%\Common Files\openv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%TEMP%\chen-cus-seaport.xls File name: %TEMP%\chen-cus-seaport.xls
Mime Type: unknown/xls
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "openv" = "%ALLUSERPROFILE%\Common Files\openv.exe"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\Timess "Timess" = "0"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\textlogsss "textlogsss" = "sunny2"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\Settimess "Settimess" = "60"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\note "note" = "enolove14.5"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\logss "logss" = "[keylog record]"HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\htt "htt" = "http://sonunigam.us/opt/mainpage.php"
Loading...