GlaceTrojan
GlaceTrojan Description
Glace is a Trojan that allows an unauthorized user some remote control over ones PC. This may result in private personal information being stolen. The Glace Trojan has the basic common features which most Trojans of its kind exhibit – it can gain access to the user’s personal and system files. Glace, however, has one added distinctive malicious feature: it will modify and change the user’s registry so that it can reinfect the user’s PC each time an a.txt file with Notepad is open.
Type: Remote Administration Tools
Automatic Detection of GlaceTrojan
GlaceTrojan has typically the following processes in memory:
- sysexplr.exe
- sysexplr.exe
GlaceTrojan creates the following registry entries:
- Software\Classes\txtfile\Shell\open\command\C:\WINDOWS\SYSTEM\Sysexplr.exe %1\
- Software\Classes\txtfile\Shell\open\command\C:\WINDOWS\SYSTEM\Sysexplr.exe %1\
- SoftwareClassesxtfileShellopencommandC:WINDOWSSYSTEMSysexplr.exe%1
- Software\Classes\txtfile\Shell\open\command\C:\WINDOWS\SYSTEM\Sysexplr.exe %1
Important Article Disclaimer

This entry was posted
on 08/6/08 and is filed under Remote Administration Tools.
You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.

English 

GlaceTrojan 










