Graftor is a family of malicious Trojan horses which pretends to be legitimate applications. It tries to connect to internet and contact various different servers without user knowledge, probably to get commands from attacker, or to download more malware.
Graftor family includes several different types of malware, some of them even pretends to be a media player. Here’s a list of things that it can do:
- Modifies autorun registry to run automatically when Windows starts
- Copies malicious executable files into its profile directory
- Installs its components in background
- Connects to a remote server without user knowledge
- Creates a hidden folder (C:\addons) and copy itself there
- Creates a new directory called "Programas21"
- Disables users ability to cancel Graftors connection to the Internet
It is very important to remove Graftor from your PC. Manual removal might not delete all files of this Trojan, so it’s recommended doing a full system scan with a reputable anti-malware software to ensure your systems security level is high.
Graftor manual removal
Delete registry values:
Remove "http://184.108.40.206/index1.php" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "http://fitness.poxyport.info" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "http://bashcontrolilimited.tecnologiaovh.com" from registry value "AutoConfigUrl" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove autorun entry "Microsofts" which is pointing to "<$WINDIR>\<$ENV(Win32Graftor3471_Filename)>.exe".
Remove autorun entry "sbthost" which is pointing to "<$APPDATA>\arquivo.exe".
The file at "<$APPDATA>\arquivo.exe
Comments on Graftor
Post a comment
Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.