Associated Malware Groups
The filename is associated with the malware groups:
- System Back Door
- Cloaked Malware
- Worm
- Malicious Software
File Behavior
GLPS.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Injects code into other processes
- Creates new folders on the system
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Found on infected systems and resists interrogation by security products
- The Process is packed and/or encrypted using a software packing process
- This Process is a file infector which modifies program files to include a copy of the infection
- Injects code into other processes
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Uses DNS to retrieve the IP address for web sites
- Visits web sites on your PC without you knowing
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Executes Processes stored in Temporary Folders
GLPS.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Copied to multiple locations on the system
- Executed from Temporary Folders
- Terminated as a Process
Country Of Origin
The filename GLPS.EXE was first seen on Mar 9 2009 in the following geographical regions of the Prevx community:
- Spain on Mar 9 2009
- El Salvador on Mar 9 2009
- Mexico on Mar 20 2009
- Europe on Aug 10 2009
- Korea, Republic of on Jan 15 2010
- The United Kingdom on Jan 15 2010
- Dominican Republic on Mar 9 2010
- Ecuador on Mar 9 2010
File Name Aliases
GLPS.EXE can also use the following file names:
- ADOBE.FLASH-INSTALL[n].EXE
- ADOBE.FLASH-INSTALL.EXE
- PLUGINVIDEO.EXE
- ACTIVE-X.INSTALLER.EXE
- ADOBE.FLASH-INSTALL(n).EXE
- NERO.BOURNING.ROM.7.ULTRA.EDITION.INCL.KEYGEN.AND.SERIAL.EXE
- ACTIVE-X.INSTALLER[n].EXE
- VIRUS/ADOBE.FLASH-INSTALL.EXE
- VIRUS/GLPS.EXE
- ADOBE.FLASH-INSTALL (n).EXE
- AUTORUN.EXE
- ACTIVEX-CONTROLER[n].EXE
- POSTALITA[n].EXE
- INSTALL_FLASH_PLAYER_9.EXE
- CONTROLADOR-ACTIVEX.ADOBE-CORPORATION.EXE
- BOT[n].EXE
- FLASH-INSTALLER-WINDOWS[n].EXE
- JAVATMP18846.EXE
- JAVATMP47890.EXE
- JAVATMP59382.EXE
- FLASH-INSTALLER-WINDOWS.EXE
- JAVATMP29498.EXE
- JAVATMP5953.EXE
- JAVATMP39001.EXE
- JAVATMP43643.EXE
- JAVATMP43645.EXE
- JAVATMP43647.EXE
- JAVATMP43649.EXE
- JAVATMP43651.EXE
- MICROSOFT.FLASH.PLAYER.EXE
- JAVATMP43450.EXE
- JAVATMP43451.EXE
- NO.PUEDO.ESTAR.SIN.TI.MP3[1].EXE
- SETUP.EXE
- FLASH-INSTALLER-WINDOWS[1].EXE
- 412.EXE
- DC36.EXE
- 764.EXE
- LDPROVRZ.EXE.PART
- KPFZW8NY.EXE.PART
- 30136638.EXE
- 89070683.ADO
- 14591522.EX_
Filesizes
The following file size has been seen:
- 124,416 bytes
- 185,550 bytes
- 103,424 bytes
- 125,440 bytes
- 147,968 bytes
File Type
The filename GLPS.EXE refers to many versions of an executable program.
File Activity
One or more files with the name GLPS.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\recycler\s-1-5-21-2372000550-0700663699-466500622-3671\Desktop.ini
- Opens/modifes c:\autoexec.bat
- Creates c:\docume~1\user\locals~1\temp\046.exe
- Creates c:\docume~1\user\locals~1\temp\jdbfkkjjkdf.bat
- Creates c:\docume~1\user\locals~1\temp\hsdjhsdw.ba
- Creates c:\windows\system32\drivers\etc\host
- Creates c:\docume~1\user\locals~1\temp\dvkdnfs.ba
Network Activity
One or more files with the name GLPS.EXE performs the following network events:
- DNS Lookup91.121.101.22 irc.ekizmedia.com
- DNS Lookup1.1.13.1 SARAH-5B8C77BC
- DNS Lookup192.193.230.100 bmxxx.notengodominio.com
- DNS Lookup148.244.43.5 puercomex.noip.es
Website Activity
One or more files with the name GLPS.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- 208 .43 .0 .156 / ~arminbou / 666 .exe
- TCP:91.121.101.22:7006 Port:27
- Port 80 IP:208.43.0.156
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.