Severity scale  

Graftor. How to Remove? (Uninstall Guide)

removal by - -   Also known as Win32.Graftor, W32/Graftor | Type: Trojans

Graftor is a family of malicious Trojan horses which pretends to be legitimate applications. It tries to connect to internet and contact various different servers without user knowledge, probably to get commands from attacker, or to download more malware.

Graftor family includes several different types of malware, some of them even pretends to be a media player. Here’s a list of things that it can do:

  • Modifies autorun registry to run automatically when Windows starts
  • Copies malicious executable files into its profile directory
  • Installs its components in background
  • Connects to a remote server without user knowledge
  • Creates a hidden folder (C:\addons) and copy itself there
  • Creates a new directory called "Programas21"
  • Disables users ability to cancel Graftors connection to the Internet

It is very important to remove Graftor from your PC. Manual removal might not delete all files of this Trojan, so it’s recommended doing a full system scan with a reputable anti-malware software to ensure your systems security level is high.

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Reimage - remover Happiness
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Graftor. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended remover to uninstall Graftor. You should confirm using free trial that it detects current version of parasite.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
We are testing Reimage's efficiency (2012-06-04 07:51)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-06-04 07:51)
Webroot SecureAnywhere AntiVirus

Graftor manual removal

Kill processes:
Delete registry values:
Remove "" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "" from registry value "AutoConfigUrl" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove autorun entry "Microsofts" which is pointing to "<$WINDIR>\<$ENV(Win32Graftor3471_Filename)>.exe".
Remove autorun entry "sbthost" which is pointing to "<$APPDATA>\arquivo.exe".
Delete files:
The file at "<$APPDATA>\arquivo.exe
Delete directories:

Information updated:

Comments on Graftor

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name


(All fields are required)