Home Malware Programs Trojans Trojan:Win32/Grymegat.A

Trojan:Win32/Grymegat.A

Posted: January 30, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 30
First Seen: January 30, 2013
OS(es) Affected: Windows

Trojan:Win32/Grymegat.A is a ransomware Trojan that locks a targeted computer and displays a webpage including a bogus full-screen image/alert that covers the whole desktop. The fake pop-up notification distributed by Trojan:Win32/Grymegat.A pretends to come from a legal institution, such as the Federal Bureau of Investigation (FBI), and accuses PC users of the imaginary downloading and spreading of illegal material. Trojan:Win32/Grymegat.A demands a ransom from victims to be paid via the legitimate payment and financial transfer service Green Dot MoneyPak to unlock the computer. Trojan:Win32/Grymegat.A can make system changes to the infected computer that make it difficult for a PC user to download, install, run, or update anti-virus software. Once installed, Trojan:Win32/Grymegat.A makes system changes by dropping potentially malicious files and modifying the Windows Registry. Trojan:Win32/Grymegat.A creates the registry entries that allow it to run its copy automatically every time you start Windows. Trojan:Win32/Grymegat.A avoids Windows Firewall so that it can create a connection to another computer system. Trojan:Win32/Grymegat.A does this by inserting itself to the list of legitimate programs that can avoid Firewall. Trojan:Win32/Grymegat.A ends several Windows system-related processes if they are presently running on the victimized computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 103.93 KB (103936 bytes)
MD5: 003269da2732b6132acd9bc21f55bb2b
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
file.exe File name: file.exe
Size: 135.16 KB (135168 bytes)
MD5: 2b6ffa9e8099933a2f61b2cf2f8704bd
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
%SystemDrive%\recycler\find_me.tmp File name: %SystemDrive%\recycler\find_me.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Update" = "%APPDATA%\System\winlogon.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Update" = "%APPDATA%\System\winlogon.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "explorer.exe, %APPDATA%\System\winlogon.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "Update" = "%APPDATA%\System\winlogon.exe"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "%APPDATA%\System\winlogon.exe" = "%APPDATA%\System\winlogon.exe:*:enabled:winlogon.exe"
Loading...