Need help? Ask the community or hire an expert.
Go to Avira Answers
Date discovered:23/03/2009
Type:Backdoor Server
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low to medium
Damage Potential:Low to medium
Static file:Yes
File size:185.550 Bytes
MD5 checksum:390d33386ec45aa4d33501ba13984669
IVDF version:

 General Aliases:
   •  Mcafee: Generic Dropper.f trojan
   •  Panda: W32/P2Pworm.AM.worm
   •  Eset: Win32/Injector.MH
   •  Bitdefender: Trojan.Generic.1802404

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003

Side effects:
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following location:
   • %recycle bin%\%CLSID%\glps.exe

 Registry One of the following values is added in order to run the process after reboot:

–  [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   • Taskman="%recycle bin%\%CLSID%\glps.exe"

 IRC To deliver system information and to provide remote control it connects to the following IRC Servers:

Server: irc.ek**********.com
Port: 7006

Port: 7006

Server: story.dn**********.com
Port: 7006

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Petre Galan on Monday, November 16, 2009
Description updated by Petre Galan on Monday, November 23, 2009

Back . . . .