Home Malware Programs Backdoors Backdoor.Grexden

Backdoor.Grexden

Posted: May 8, 2014

Threat Metric

Ranking: 11,612
Threat Level: 1/10
Infected PCs: 1,349
First Seen: May 8, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows


Backdoor.Grexden is a backdoor Trojan that may open a back door on the infected computer. Backdoor.Grexden is typically dropped by a specially crafted document which exploits the Microsoft Windows Common Controls ActiveX Control Remote Code Execution Vulnerability (CVE-2012-0158). When Backdoor.Grexden is executed, it creates potentially malicious files.Backdoor.Grexden also creates registry entries under the certain registry subkey. Backdoor.Grexden then connects to the remote locations. Backdoor.Grexden may then execute potentially malicious actions on the PC such as download files, create processes, move files and enumerate the file system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Documents and Settings\<username>\Application Data\Microsoft\Network\encrypt.dat File name: C:\Documents and Settings\<username>\Application Data\Microsoft\Network\encrypt.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
C:\Documents and Settings\<username>\Application Data\Microsoft\Network\MSNETWORK.DLL File name: C:\Documents and Settings\<username>\Application Data\Microsoft\Network\MSNETWORK.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
Loading...