Skip to main content

Trojan-Proxy:W32/Grum.A

Classification

Category:

Malware

Type:

Trojan-proxy

Aliases:

  • Trojan-Proxy:W32/Grum.A

Summary

This trojan allows unauthorized parties to use the infected computer as a proxy server to anonymously access the Internet.

Removal

Technical Details

Trojan-Proxy:W32/Grum.A may arrive in the system in a spam email message containing an image that links to the real malware.

Here is the image associated with the message:

This malware is hosted at the following links:

  • http://tvz-archive.com/I[REMOVED}.exe
  • http://abnoba.net/I[REMOVED]0.exe

Installation

If the user executes the file they are directed to by the spam message, it creates a copy of itself on the user's computer at the following path and filename:

  • %temp%\winlogon.exe

Grum.A uses the following batch file created on the same directory where the malware was to delete the executed copy of itself:

  • sys.bat

To enable automatic execution upon system boot, it adds the following auto start registry:

  • HKCU\\Software\Microsoft\Windows\CurrentVersion\Run Firewall auto setup = %temp%\winlogon.exe

Note: %temp% is the temporary windows folder:

Activity

Once installed, Grum.A serves as a proxy server that communicates to the following address:

  • 72.232.49.214

Commands from the server may include downloading of files and spamming mails.

Stealth

Grum.A is a kernel malware that hooks several ntdll APIs to hide its file and process.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.