Home Malware Programs Trojans Trojan:Win32/Grymegat.B

Trojan:Win32/Grymegat.B

Posted: January 30, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 31
First Seen: January 30, 2013
OS(es) Affected: Windows

Trojan:Win32/Grymegat.B is a Trojan that is not able to propagate on its own. Trojan:Win32/Grymegat.B may perform numerous actions chosen by an attacker on an infected computer system. Once installed on the targeted PC, Trojan:Win32/Grymegat.B makes system changes by dropping potentially malicious files and making registry modifications. Trojan:Win32/Grymegat.B modifies the registry entries so that its copy can be executed automatically every time you start Windows. Trojan:Win32/Grymegat.B changes system security settings by disabling the LUA (Least Privileged User Account), also known as the 'administrator in Admin Approval Mode' user type, by making registry modifications. Disabling the LUA enables all programs to run by default with all administrative privileges, without the PC user being urged for explicit consent. Trojan:Win32/Grymegat.B contacts a remote host to report a new infection to its author, to download and execute arbitrary files (involving updates or additional malware threats), to receive configuration or other data, to receive instructions from remote attackers and to upload data taken from the infected computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 75.77 KB (75776 bytes)
MD5: 58098e72ad3fa4372115cbc15dbcd1ba
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
file.exe File name: file.exe
Size: 62.46 KB (62464 bytes)
MD5: 03b4bbd4b7e6f0403dc6d215d6bdc6b7
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
file.exe File name: file.exe
Size: 114.68 KB (114688 bytes)
MD5: 0d971da1fd0295eae02638bc5278b94d
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
C:\Documents and Settings\<username>\start menu\programs\startup\iexplore.lnk File name: C:\Documents and Settings\<username>\start menu\programs\startup\iexplore.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\application data\system\system.exe File name: C:\Documents and Settings\<username>\application data\system\system.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\application data\rt1.jpg File name: C:\Documents and Settings\<username>\application data\rt1.jpg
Mime Type: unknown/jpg
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "explorer.exe, c:\documents and settings\administrator\application data\system\system.exe" "EnableLUA" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "EnableLUA" = "0"
Loading...