Home Malware Programs Adware GrassMow

GrassMow

Posted: September 4, 2014

Threat Metric

Ranking: 17,084
Threat Level: 2/10
Infected PCs: 220
First Seen: September 2, 2014
Last Seen: July 21, 2023
OS(es) Affected: Windows


GrassMow is an unwanted program that could be considered as adware by many computer security researchers. Through the actions of GrassMow it may be found that it is annoying by loading up several ads in pop-up or banner formats when surfing the internet. The GrassMow ads may then consist of various offers or products that prove to be enticing to many computer users. Use of the GrassMow ads by clicking on them may then cause redirects by web browsers where pages or sites with questionable content are loaded. It is believed that the actions of GrassMow are to gain traffic to specific sits for the purposes of gaining money through impressions and clicks on ads. Stopping the activities of GrassMow may require use of an antimalware tool to seek out GrassMow and its related components and remove them all automatically.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



grassmowSetup.exe File name: grassmowSetup.exe
Size: 582.77 KB (582776 bytes)
MD5: 7f7c46682451f1642699352991971b20
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{12EF4F7F-6C80-4AC9-976B-A4EE342815C5}SOFTWARE\Microsoft\Tracing\grassmow_RASAPI32SOFTWARE\Microsoft\Tracing\grassmow_RASMANCSSOFTWARE\Microsoft\Tracing\updategrassmow_RASAPI32SOFTWARE\Microsoft\Tracing\updategrassmow_RASMANCSSOFTWARE\Microsoft\Tracing\utilgrassmow_RASAPI32SOFTWARE\Microsoft\Tracing\utilgrassmow_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\grassmow_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\grassmow_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updategrassmow_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updategrassmow_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilgrassmow_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilgrassmow_RASMANCS

Additional Information

The following directories were created:
%PROGRAMFILES%\grassmow%PROGRAMFILES(x86)%\grassmow%Temp%\grassmow
Loading...