Home Malware Programs Adware Adware.Grabrez

Adware.Grabrez

Posted: February 5, 2014

Threat Metric

Ranking: 14,590
Threat Level: 2/10
Infected PCs: 44,217
First Seen: February 5, 2014
Last Seen: December 27, 2024
OS(es) Affected: Windows


Grabrez Screenshot 1Adware.Grabrez is adware that may show pop-up ads, discount coupons, deals, offers and sponsored links via a pop-up box on social networking and online shopping websites that PC users are visiting. The Adware.Grabrez pop-up advertisements and messages may be shown as boxes, which may encompass a variety of deals and offers which, when clicked, may forcibly reroute PC users to unknown websites that may be commercial. The websites affiliated with Adware.Grabrez were designed to probably generate advertising revenue from clicks on ads and raised website traffic. When installed on the PC, Adware.Grabrez may insert a browser extension, add-on or plug-in for Internet Explorer, Mozilla Firefox and Google Chrome Web browsers when computer users install a variety of freeware that might had added into their installation Adware.Grabrez. When PC users install freeware, they may also install Adware.Grabrez on the computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\wStLibG64.sys.vir File name: wStLibG64.sys.vir
Size: 61.11 KB (61112 bytes)
MD5: 53b96ea5a332ca4df80ccc8e278e0a3f
Detection count: 4,307
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\wStLibG64.sys.vir
Group: Malware file
Last Updated: June 28, 2022
%WINDIR%\System32\drivers\wStLibG.sys File name: wStLibG.sys
Size: 52.92 KB (52920 bytes)
MD5: 32241f10e465c84b6bcfca76b87d69a6
Detection count: 3,539
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 7, 2018
%WINDIR%\System32\drivers\wStLibG64.sys File name: wStLibG64.sys
Size: 61.11 KB (61112 bytes)
MD5: a5dba1cb7be608c49b5465678a45265d
Detection count: 2,054
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: December 28, 2018
%PROGRAMFILES(x86)%\GrabRez\bin\XTLSApp.exe File name: XTLSApp.exe
Size: 94.48 KB (94488 bytes)
MD5: ba82153e9ddc8d11c3f00d6c144fb66b
Detection count: 333
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GrabRez\bin
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES%\GrabRez\GrabRez.FirstRun.exe File name: GrabRez.FirstRun.exe
Size: 1.72 MB (1726744 bytes)
MD5: e3161975f901b2d48089e909a51d6862
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GrabRez
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES(x86)%\GrabRez\bin\GrabRez.PurBrowse64.exe File name: GrabRez.PurBrowse64.exe
Size: 287 KB (287000 bytes)
MD5: e2c6ffc4a7d91cff502a472bb1893d21
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GrabRez\bin
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES%\GrabRez\bin\GrabRez.PurBrowse.exe File name: GrabRez.PurBrowse.exe
Size: 239.38 KB (239384 bytes)
MD5: 7aca8bd6e9203d693091e496cf85500d
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GrabRez\bin
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES(x86)%\GrabRez\bin\utilGrabRez.exe File name: utilGrabRez.exe
Size: 317.72 KB (317720 bytes)
MD5: 043c67f7bbed481475682aca90541e2b
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GrabRez\bin
Group: Malware file
Last Updated: June 13, 2014
%TEMP%\GrabRez\GrabRez_Setup.exe File name: GrabRez_Setup.exe
Size: 2.16 MB (2160032 bytes)
MD5: cedcfa3d212aa879d13459045e65bdb1
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\GrabRez
Group: Malware file
Last Updated: February 19, 2014
%PROGRAMFILES%\GrabRez\bin\GrabRezBrowserFilter.exe File name: GrabRezBrowserFilter.exe
Size: 42.26 KB (42264 bytes)
MD5: afc0081b89de3cc7840154fd5d149353
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GrabRez\bin
Group: Malware file
Last Updated: February 19, 2014
C:\AdwCleaner\Quarantine\C\Program Files (x86)\GrabRez\GrabRezBHO.dll.vir File name: GrabRezBHO.dll.vir
Size: 249.62 KB (249624 bytes)
MD5: 7aeaf8b388774f1a8029c0cae434bf8a
Detection count: 21
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\GrabRez\GrabRezBHO.dll.vir
Group: Malware file
Last Updated: June 5, 2024

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{6C7BB828-4CF1-4C42-8028-7D15996DEA0E}{A7A47A0B-0338-407A-88CC-04F303AE7BBC}{e1420d09-acc8-4efd-9965-e7ae3c5b977c}HKEY..\..\..\..{RegistryKeys}Software\GrabRezSoftware\Microsoft\Internet Explorer\Approved Extensions\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}SOFTWARE\Microsoft\Tracing\GrabRez_RASAPI32SOFTWARE\Microsoft\Tracing\GrabRez_RASMANCSSOFTWARE\Microsoft\Tracing\updateGrabRez_RASAPI32SOFTWARE\Microsoft\Tracing\updateGrabRez_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e1420d09-acc8-4efd-9965-e7ae3c5b977c}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{e1420d09-acc8-4efd-9965-e7ae3c5b977c}SOFTWARE\Wow6432Node\GrabRezSOFTWARE\Wow6432Node\Microsoft\Tracing\GrabRez_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\GrabRez_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateGrabRez_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateGrabRez_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e1420d09-acc8-4efd-9965-e7ae3c5b977c}SYSTEM\ControlSet001\services\eventlog\Application\Update GrabRezSYSTEM\ControlSet001\services\Update GrabRezSYSTEM\ControlSet002\services\eventlog\Application\Update GrabRezSYSTEM\ControlSet002\services\Update GrabRezSYSTEM\CurrentControlSet\services\eventlog\Application\Update GrabRezSYSTEM\CurrentControlSet\services\Update GrabRezHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GrabRez

Additional Information

The following directories were created:
%ProgramFiles%\GrabRez%ProgramFiles(x86)%\GrabRez
The following URL's were detected:
GrabRez
Loading...