GoverLAN

GoverLAN is a remote control tool that manages and controls PCs or networks from a remote location. It can be used to harm users on the same network.

General information:

Malware Name: GoverLAN
Malware Type: Remote Control Tool
Company Name: PJ Technologies, Inc
Company URL: http://pjtec.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

PJ Technologies, Inc provides you the software GoverLAN that is a remote administration tool and enterprise desktop management suite for Windows NT and Active Directory platforms. It is for use by enterprise administrators, system administrators, and technical support teams. Use GoverLAN to execute real-time remote administration and troubleshooting on your users, computers and groups. GoverLAN is so rich in remote administration features that once you try it, you will wonder how you ever did without it.

Spyware Description:

GoverLAN is a remote control tool that manages and controls PCs or networks from a remote location. It can be used to harm users on the same network.

Characteristics/Symptoms:

    -> It manages and controls PCs or networks from a remote location. -> It can be used to harm users on the same network.

Additional information might be found here:

google Search at Google for GoverLAN
bing Search at Bing for GoverLAN
yahoo Search at Yahoo for GoverLAN

Processes Running:

GoverLAN.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\GoverLAN v5.5\GovAppLog.dll 45056 Application Extension
C:\Program Files\GoverLAN v5.5\GovBase.dll 1105920 Application Extension
C:\Program Files\GoverLAN v5.5\Govcmn.dll 479232 Application Extension

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Application Data\GoverLAN\ScopeAction
C:\Program Files\GoverLAN v5.5\GoverLAN Client Agent Installe

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}\InprocServer32 InprocServer32
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}\InprocServer32 ThreadingModel
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\Installer\Products\2BC4ABF91EEDAE24FACA7B79889A5D83 ProductName