Home Malware Programs Adware GreyGray

GreyGray

Posted: October 8, 2013

Threat Metric

Ranking: 10,397
Threat Level: 2/10
Infected PCs: 3,757
First Seen: October 8, 2013
Last Seen: September 24, 2023
OS(es) Affected: Windows

GreyGray is adware that claims to improve your search results, although its functions appear to be centered on the provision of various advertisements in your Web browser. While malware experts don't see sufficient evidence to classify advertisements from GreyGray as definitively ill intended, they do typically advise PC users to avoid any unneeded interactions with advertisements that are derived from sources that are less than perfectly trustworthy. Finally, GreyGray, like most other kinds of adware, sometimes may be installed without your permission, and in such a situation, the use of anti-malware programs for deleting GreyGray (as well as any other applications that may be connected to GreyGray) should be considered necessary for the security of your computer.

The Shade of Gray that's Coming to Visit Your Browser

While notorious legends of 'gray' aliens abducting sleepers remain active and vivid images of fantasy in the public consciousness, GreyGray acts as a crude online equivalent by revealing itself when GreyGray rarely is wanted and using the opportunity to display advertisements in your browser when you least expect them to be there. GreyGray only is categorized as adware and, therefore, does not display the highly invasive or suspicious functions of a Trojan, rootkit or worm. However, an average GreyGray installation has been known to cause plenty of advertisement-related problems for all affected browsers, potentially including:

  • Redirecting you to GreyGray search results or injecting GreyGray's search results into the searches of other search engine websites.
  • Displaying advertisement banners atop unrelated Web pages.
  • Injecting links into the text of unrelated sites for the purpose of promoting sponsored/affiliated content.

In the end, while GreyGray may provide some legitimate Web-searching and shopping features, any benefits that GreyGray has to give will be dwarfed by GreyGray's disadvantages. Currently, GreyGray is labeled as adware and a Potentially Unwanted Program, or PUP.

Bringing Some Color to a Browser Dimmed by Gray

Although GreyGray certainly isn't capable of launching any high-level attacks against your computer, GreyGray and other forms of common adware are rated as basic security risks that invade your browser settings to no good end, and it is recommended uninstalling them whenever they're seen. Because adware programs often include sloppy or outright dysfunctional uninstallation protocols, you should consider the use of anti-malware tools for making sure that you can delete GreyGray and all browser changes caused by GreyGray without any long term problems.

GreyGray may be installed either through the installation process of another program (through a bundler) or by a separate PC threat. If you suspect the latter to be the case, GreyGray is unlikely to be the only thing that's been installed without your permission, and particularly thorough anti-malware scans are advised. However, safe Web-browsing habits and appropriate security software both are effective at preventing GreyGray's ingress into your computer through either method.

Aliases

MalSign.GreyGray [AVG]Riskware/BrowseFox [Fortinet]Trojan/Win32.Zapchast [AhnLab-V3]Artemis!48CDB8D668B1 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\GreyGray\bin\utilGreyGray.exe File name: utilGreyGray.exe
Size: 102.16 KB (102168 bytes)
MD5: 6f6228f026f11fc9ce875db82d8aa606
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GreyGray\bin
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES%\GreyGray\updateGreyGray.exe File name: updateGreyGray.exe
Size: 66.32 KB (66328 bytes)
MD5: cf88d876930bb20033d9474a6e37150d
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GreyGray
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES%\GreyGray\GreyGraybho.dll File name: GreyGraybho.dll
Size: 249.62 KB (249624 bytes)
MD5: 3f2df8731522b13feacda4f2be0a7893
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\GreyGray
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES(x86)%\GreyGray\bin\utilGreyGray.exe File name: utilGreyGray.exe
Size: 66.32 KB (66328 bytes)
MD5: dc62c28753f06d144c6bb8ab158788d3
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GreyGray\bin
Group: Malware file
Last Updated: February 11, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{630BB364-173F-49E6-8510-6E0C86B25593}{ae60e6ed-49dd-4099-8b5e-386a4908d5d5}{FE34FA86-9846-47AA-8E21-108C4D3EB7B1}HKEY..\..\..\..{RegistryKeys}Software\GreyGraySoftware\Microsoft\Internet Explorer\Approved Extensions\{AE60E6ED-49DD-4099-8B5E-386A4908D5D5}SOFTWARE\Microsoft\Tracing\updateGreyGray_RASAPI32SOFTWARE\Microsoft\Tracing\updateGreyGray_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ae60e6ed-49dd-4099-8b5e-386a4908d5d5}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE60E6ED-49DD-4099-8B5E-386A4908D5D5}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE60E6ED-49DD-4099-8B5E-386A4908D5D5}SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GreyGraySOFTWARE\Wow6432Node\GreyGraySOFTWARE\Wow6432Node\Microsoft\Tracing\updateGreyGray_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateGreyGray_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ae60e6ed-49dd-4099-8b5e-386a4908d5d5}SYSTEM\ControlSet001\services\eventlog\Application\Update GreyGraySYSTEM\ControlSet001\services\Update GreyGraySYSTEM\ControlSet001\Services\Util GreyGraySYSTEM\ControlSet002\Services\Util GreyGraySYSTEM\CurrentControlSet\services\eventlog\Application\Update GreyGraySYSTEM\CurrentControlSet\services\Update GreyGraySYSTEM\CurrentControlSet\Services\Util GreyGray

Additional Information

The following directories were created:
%PROGRAMFILES%\GreyGray%PROGRAMFILES(x86)%\GreyGray
Loading...