GoverLAN
GoverLAN is a remote control tool that manages and controls PCs or networks from a remote location. It can be used to harm users on the same network.
General information:
Malware Name: |
GoverLAN |
Malware Type: |
Remote Control Tool |
Company Name: |
PJ Technologies, Inc |
Company URL: |
http://pjtec.com/
|
Threat Level: |
Low Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
PJ Technologies, Inc provides you the software GoverLAN that is a remote administration tool and enterprise desktop management suite for Windows NT and Active Directory platforms. It is for use by enterprise administrators, system administrators,
and technical support teams. Use GoverLAN to execute real-time remote administration and troubleshooting on your users, computers and groups. GoverLAN is so rich in remote administration features that once you try it, you will wonder how you ever
did without it.
Spyware Description:
GoverLAN is a remote control tool that manages and controls PCs or networks from a remote location. It can be used to harm users on the same network.
Characteristics/Symptoms:
-> It manages and controls PCs or networks from a remote location. -> It can be used to harm users on the same network.
Additional information might be found here:
Processes Running:
GoverLAN.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Program Files\GoverLAN v5.5\GovAppLog.dll |
45056 |
Application Extension |
C:\Program Files\GoverLAN v5.5\GovBase.dll |
1105920 |
Application Extension |
C:\Program Files\GoverLAN v5.5\Govcmn.dll |
479232 |
Application Extension |
Folder information Created after Installation:
Folder Location |
C:\Documents and Settings\[USER]\Application Data\GoverLAN\ScopeAction |
C:\Program Files\GoverLAN v5.5\GoverLAN Client Agent Installe |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}\InprocServer32 |
InprocServer32 |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}\InprocServer32 |
ThreadingModel |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Classes\Installer\Products\2BC4ABF91EEDAE24FACA7B79889A5D83 |
ProductName |