Title: Graftor
Type: Trojans
Also known as: Win32.Graftor, W32/Graftor

Remove Graftor
Removal instructions

Severity scale:Graftor severity is 45  (45 / 100)

Graftor is a family of malicious Trojan horses which pretends to be legitimate applications. It tries to connect to internet and contact various different servers without user knowledge, probably to get commands from attacker, or to download more malware.

Graftor family includes several different types of malware, some of them even pretends to be a media player. Here’s a list of things that it can do:

  • Modifies autorun registry to run automatically when Windows starts
  • Copies malicious executable files into its profile directory
  • Installs its components in background
  • Connects to a remote server without user knowledge
  • Creates a hidden folder (C:\addons) and copy itself there
  • Creates a new directory called "Programas21"
  • Disables users ability to cancel Graftors connection to the Internet

It is very important to remove Graftor from your PC. Manual removal might not delete all files of this Trojan, so it’s recommended doing a full system scan with a reputable anti-malware software to ensure your systems security level is high.

Automatic Graftor removal:

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software to remove Graftor you agree with our Privacy Policy and Agreement of Use.
SpyHunter is recommended remover to uninstall Graftor. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

If you failed to remove Graftor using SpyHunter, submit question to our support team and provide as much details as possible.
manual required
We are testing STOPzilla's efficiency at removing Graftor (2012-06-04 07:51:08)
Malwarebytes Anti Malware
manual required
We are testing Malwarebytes Anti Malware's efficiency at removing Graftor (2012-06-04 07:51:08)
XoftSpySE Anti Spyware
manual required
We are testing XoftSpySE Anti Spyware's efficiency at removing Graftor (2012-06-04 07:51:08)
Defender Pro Ultimate
manual required
We are testing Defender Pro Ultimate's efficiency at removing Graftor (2012-06-04 07:51:08)

what to do if you failed to remove the infection?
Virus Removal
Phone Support
Help Line to remove Graftor
Graftor snapshot:

Graftor manual removal:

Kill processes:
Delete registry values:
Remove "" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "http://fitness.poxyport.info" from registry value "AutoConfigURL" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove "http://bashcontrolilimited.tecnologiaovh.com" from registry value "AutoConfigUrl" at "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\".
Remove autorun entry "Microsofts" which is pointing to "<$WINDIR>\<$ENV(Win32Graftor3471_Filename)>.exe".
Remove autorun entry "sbthost" which is pointing to "<$APPDATA>\arquivo.exe".
Delete files:
The file at "<$APPDATA>\arquivo.exe
Delete directories:

QR code for Graftor removal instructions:

Graftor qrcode
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.

The reason we add QR code to the website is that parasites like Graftor are really hard to remove on infected computer. you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Graftor right in your pocket.

Simply use the QR scanner and read removal instructions from mobile device.
Information added: 2012-06-04 07:51:08
Information updated: 2012-06-04 07:51:08

Additional resources:

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

Post Comment:

Attention: Use this form only if you have additional information about Graftor parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name


* All field required
Like us on Facebook
Latest spyware news:
Subscribe to spyware news
Please enter your e-mail address:
If you do not want to receive our spyware
newsletter please unsubscribe here
48651 Subscribers
Ask us
I failed to remove Graftor using SpyHunter.



Spreading the knowledge:

It is very hard to fight against computer parasites on the Internet alone. If you have a website, we would be more than happy if you would like to cooperate and help us spread the information about latest threats. Remember, knowledge is the most powerful weapon. Help your visitors protect their computers!
add text box
rss feed
help other