Severity scale:  
  (45/100)

Graftor. How to remove? (Uninstall guide)

removal by Jake Doevan - -   Also known as Win32.Graftor, W32/Graftor | Type: Trojans
12

Graftor is a family of malicious Trojan horses which pretends to be legitimate applications. It tries to connect to internet and contact various different servers without user knowledge, probably to get commands from attacker, or to download more malware.

Graftor family includes several different types of malware, some of them even pretends to be a media player. Here’s a list of things that it can do:

  • Modifies autorun registry to run automatically when Windows starts
  • Copies malicious executable files into its profile directory
  • Installs its components in background
  • Connects to a remote server without user knowledge
  • Creates a hidden folder (C:\addons) and copy itself there
  • Creates a new directory called “Programas21”
  • Disables users ability to cancel Graftors connection to the Internet

It is very important to remove Graftor from your PC. Manual removal might not delete all files of this Trojan, so it’s recommended doing a full system scan with a reputable anti-malware software to ensure your systems security level is high.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Graftor you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Graftor. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.
Alternate Software
Plumbytes Anti-Malware
We have tested Plumbytes Anti-Malware's efficiency in removing Graftor (2012-06-04)
Malwarebytes Anti Malware
We have tested Malwarebytes Anti Malware's efficiency in removing Graftor (2012-06-04)
Hitman Pro
We have tested Hitman Pro's efficiency in removing Graftor (2012-06-04)
Webroot SecureAnywhere AntiVirus
We have tested Webroot SecureAnywhere AntiVirus's efficiency in removing Graftor (2012-06-04)

Graftor manual removal:

Kill processes:
arquivo.exe

modpro.exe

Delete registry values:
Remove "http://187.109.161.62/index1.php" from registry value "AutoConfigURL" at "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings".

Remove "http://fitness.poxyport.info" from registry value "AutoConfigURL" at "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings".

Remove "http://bashcontrolilimited.tecnologiaovh.com" from registry value "AutoConfigUrl" at "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings".

Remove autorun entry "Microsofts" which is pointing to "<$WINDIR><$ENV(Win32Graftor3471_Filename)>.exe".

Remove autorun entry "sbthost" which is pointing to "<$APPDATA>arquivo.exe".

Delete files:
The file at "<$APPDATA>arquivo.exe

Delete directories:
C:Programas21

C:addons