GreyGray

GreyGray Description

There have been numerous complaints involving GreyGray redirects and pop-up advertisements. GreyGray is a PUP (Potentially Unwanted Program). GreyGray is created by Super Web LLC, an entity that has been responsible for several known adware. Applications developed by Super Web LLC are often part of low quality marketing efforts. In most cases, PUPs like GreyGray are bundled with freeware distributed by low quality software developers or marketers. In many cases, GreyGray may be installed without permission, although technically, computer users often have the option of opting out of installing GreyGray. However, this option is hidden in some way or made hard to find. Once the GreyGray PUP is installed, GreyGray adds advertising content to unrelated websites.

Advertising and Marketing Content Associated with GreyGray


The GreyGray PUP has been associated with several types of online marketing. The GreyGray PUP has been linked to the following types of advertising strategies:
  • GreyGray has been associated with search-related advertising schemes. For example, search engines on the affected Web browser may display sponsored search results. These search results will appear when computer users carry out a search, despite not being related to the search terms at all. GreyGray has a search component itself. However, security researchers have observed that the GreyGray search function is quite unreliable and is meant specifically to drive traffic to its associated websites.
  • GreyGray has also been known to add advertising content to unrelated websites. For example, GreyGray may add an additional banner to the victim's Web browser, which may display a banner whenever the computer user visits other Web pages. GreyGray may also add in-line text advertisements to other content. Other types of advertisements associated with GreyGray include pop-up window advertisements and sliding advertisements that appear on the bottom of the affected Web browser window. GreyGray has also been associated with redirects that may appear when trying to connect to unrelated Web pages.
  • Despite other symptoms associated with GreyGray, GreyGray may cause Internet connectivity and browser performance problems.

Aliases: a variant of Win32/BrowseFox.G [ESET-NOD32], Artemis!48CDB8D668B1 [McAfee], MalSign.GreyGray [AVG], Riskware/BrowseFox [Fortinet], Trojan/Win32.Zapchast [AhnLab-V3] and TROJ_GEN.F47V0125 [TrendMicro-HouseCall].

Infected with GreyGray? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect GreyGray

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of GreyGray outbreaks and other threats from global to local level.

File System Details

GreyGray creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES(x86)%\GreyGray\bin\utilGreyGray.exe 97,048 411b3972503e74067ca80798d34771e6 484
2 chrome-extension_nhogbcndagiknbfomjgdeghehkljalhi_0.localstorage 46
3 chrome-extension_nhogbcndagiknbfomjgdeghehkljalhi_0.localstorage-journal 45
4 %PROGRAMFILES(x86)%\GreyGray 43
5 %PROGRAMFILES%\GreyGray 42
6 %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Extension Settings\nhogbcndagiknbfomjgdeghehkljalhi 41
7 %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nhogbcndagiknbfomjgdeghehkljalhi 40
8 %PROGRAMFILES%\GreyGray\GreyGrayBHO.dll 249,624 e517a30a6335ebe95c07d65f7b59381e 8
9 %PROGRAMFILES(x86)%\GreyGray\bin\GreyGrayBrowserFilter.exe 42,264 0becbd964c9b73d0ff3095697d97e6c7 4
10 %PROGRAMFILES(x86)%\GreyGray\updateGreyGray.exe 65,304 28e653d12d49c337767c61cb01151ad9 1,384

Registry Details

GreyGray creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ae60e6ed-49dd-4099-8b5e-386a4908d5d5}
SOFTWARE\Microsoft\Tracing\updateGreyGray_RASMANCS
SOFTWARE\Microsoft\Tracing\updateGreyGray_RASAPI32
SOFTWARE\Google\Chrome\Extensions\nhogbcndagiknbfomjgdeghehkljalhi
SYSTEM\CurrentControlSet\services\Update GreyGray
SYSTEM\CurrentControlSet\services\eventlog\Application\Update GreyGray
SYSTEM\ControlSet001\services\Update GreyGray
SYSTEM\ControlSet001\services\eventlog\Application\Update GreyGray
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateGreyGray_RASAPI32
SOFTWARE\Wow6432Node\GreyGray
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nhogbcndagiknbfomjgdeghehkljalhi
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GreyGray
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE60E6ED-49DD-4099-8B5E-386A4908D5D5}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE60E6ED-49DD-4099-8B5E-386A4908D5D5}
Software\GreyGray
Software\Microsoft\Internet Explorer\Approved Extensions, value: {AE60E6ED-49DD-4099-8B5E-386A4908D5D5}
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{630BB364-173F-49E6-8510-6E0C86B25593}
{ae60e6ed-49dd-4099-8b5e-386a4908d5d5}
{FE34FA86-9846-47AA-8E21-108C4D3EB7B1}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 2 + 14 ?