Threat Database Trojans Trojan:Win32/Glod.A

Trojan:Win32/Glod.A

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 5
First Seen: June 19, 2013
Last Seen: May 5, 2023
OS(es) Affected: Windows

Trojan:Win32/Glod.A is a Trojan, which control what keys an attacked computer user hits and transmits this information to a remote cybercriminal. Trojan:Win32/Glod.A can obtain remote unauthorized access to the victimized computer user's user names and passwords. Trojan:Win32/Glod.A may be installed on the corrupted PC by masquerading as a genuine software product, or by other security threats. Trojan:Win32/Glod.A may steal the victim's personal information, incorporating his/her usernames and passwords. Once installed on the compromised PC, Trojan:Win32/Glod.A makes system alterations by downloading malicious files and modifying the Windows Registry. Trojan:Win32/Glod.A may use social engineering to induce the target PC user to install it on the vulnerable computer system. Trojan:Win32/Glod.A can masquerade as a screen saver file 'image.scr', or it may also be downloaded by other security infections. Once run, Trojan:Win32/Glod.A controls and logs keystrokes and active windows as the affected computer user uses the attacked PC. Trojan:Win32/Glod.A then transfers this information to a remote attacker at the particular domain.

File System Details

Trojan:Win32/Glod.A may create the following file(s):
# File Name Detections
1. %ALLUSERPROFILE%\Common Files\openv.exe
2. %TEMP%\chen-cus-seaport.xls

Registry Details

Trojan:Win32/Glod.A may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\htt "htt" = "http://sonunigam.us/opt/mainpage.php"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\Settimess "Settimess" = "60"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\babag "babag" = "United States"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\note "note" = "enolove14.5"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\Timess "Timess" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "openv" = "%ALLUSERPROFILE%\Common Files\openv.exe"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\logss "logss" = "[keylog record]"
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\C:\Documents and Settings\All Users\Common Files\textlogsss "textlogsss" = "sunny2"

Trending

Most Viewed

Loading...