Home Malware Programs Trojans Graftor

Graftor

Posted: June 4, 2012

Threat Metric

Ranking: 6,784
Threat Level: 8/10
Infected PCs: 145,669
First Seen: October 13, 2011
Last Seen: October 2, 2023
OS(es) Affected: Windows

Graftor is a Trojan, which poses as a legitimate software program. Graftor attempts to connect to the internet and contact numerous remote servers without the affected PC user permission and knowledge, likely to receive instructions from the hacker, or to drop more malware threats. Graftor modifies the 'autorun' registry so that it can load automatically every time you start Windows. Graftor copies malicious executable files into its profile directory. Graftor also installs its components in the system background.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\system32\config\systemprofile\AppData\Roaming\svrupg.exe File name: svrupg.exe
Size: 2.76 MB (2767872 bytes)
MD5: 1b69c9bcc5358d9a98e4aa7707ffd8f7
Detection count: 4,787
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\config\systemprofile\AppData\Roaming\svrupg.exe
Group: Malware file
Last Updated: October 11, 2022
C:\Program Files (x86)\Kilchwobigh\klcUpd.dll File name: klcUpd.dll
Size: 328.19 KB (328192 bytes)
MD5: 94ddc69fced08a6ed5d735027e815ec4
Detection count: 2,672
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Kilchwobigh\klcUpd.dll
Group: Malware file
Last Updated: December 13, 2021
C:\Windows\Temp\04095\conhost.exe File name: conhost.exe
Size: 1.26 MB (1265152 bytes)
MD5: 60f7cb231a831ca5cda342020a5208ce
Detection count: 2,415
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\04095\conhost.exe
Group: Malware file
Last Updated: June 22, 2022
%APPDATA%\service.exe File name: service.exe
Size: 1.73 MB (1738240 bytes)
MD5: 29b4d30fc9fe15bf410632820e0e2e9d
Detection count: 742
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 4, 2016
%APPDATA%\service90132.exe File name: service90132.exe
Size: 1.93 MB (1936896 bytes)
MD5: 2915096fb3ccada63b983f9c68515bc8
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 30, 2020
%ALLUSERSPROFILE%\conhost.exe File name: conhost.exe
Size: 1.6 MB (1608704 bytes)
MD5: e94b741bb1172f5284157a0f2ac7bf80
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 19, 2016
%SYSTEMDRIVE%\Users\<username>\959403039485030\winupd32cfg.exe File name: winupd32cfg.exe
Size: 89.48 KB (89484 bytes)
MD5: c78924cc0e6b440b5460f04f4aaf17d1
Detection count: 148
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\959403039485030\winupd32cfg.exe
Group: Malware file
Last Updated: April 27, 2022
dir\name.exe File name: name.exe
Size: 738.3 KB (738304 bytes)
MD5: 540f9456415ec88e2ab9f5ac635d28e7
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: dir
Group: Malware file
Last Updated: September 19, 2017
%ALLUSERSPROFILE%\Application Data\service.exe File name: service.exe
Size: 1.8 MB (1803264 bytes)
MD5: e1de11c2ab6cef8f4c716ea8d28455d5
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: March 9, 2016
%ALLUSERSPROFILE%\service.exe File name: service.exe
Size: 1.76 MB (1762304 bytes)
MD5: 8d99bbc5ef76f7327829f80a15f21f62
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 9, 2016
%WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming\svrupg.exe File name: svrupg.exe
Size: 2.76 MB (2767360 bytes)
MD5: 9736f01415c8ff5c1a0b14c54cdc802e
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2016
%WINDIR%\system32\config\systemprofile\AppData\Roaming\svrupg.exe File name: svrupg.exe
Size: 2.76 MB (2767872 bytes)
MD5: f0c179316ccfc4ad54287fbb6e8b99bf
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2016
%ALLUSERSPROFILE%\msiqljp.exe File name: msiqljp.exe
Size: 46.26 KB (46260 bytes)
MD5: 0566e2efd6b6f189c2cf9a44ebc417de
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 23, 2016
%ALLUSERSPROFILE%\service.exe File name: service.exe
Size: 1.74 MB (1746432 bytes)
MD5: a10fe1bb15a5c2f29f55b8338140acfd
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 9, 2016
C:\Windows\Temp\gAC93.tmp.exe File name: gAC93.tmp.exe
Size: 151.55 KB (151552 bytes)
MD5: b7f5f8489ce01c4b11ac530f24b07555
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\gAC93.tmp.exe
Group: Malware file
Last Updated: April 23, 2022
%PROGRAMFILES%\22cc3ef3650630662937132a51b94f7c\20d19e546d1f3082e70434b98145cc8c.exe File name: 20d19e546d1f3082e70434b98145cc8c.exe
Size: 818.68 KB (818688 bytes)
MD5: 26ca0dfcfde6b929d4385b6c1ba6c71f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\22cc3ef3650630662937132a51b94f7c
Group: Malware file
Last Updated: July 3, 2018
%ALLUSERSPROFILE%\Application Data\service.exe File name: service.exe
Size: 1.83 MB (1836477 bytes)
MD5: 96c42dedbc807b388d45057b06b3354e
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: March 9, 2016
%ALLUSERSPROFILE%\msdtabc.exe File name: msdtabc.exe
Size: 1.3 MB (1308655 bytes)
MD5: 53371ed43ea4d4b1a3401fa3f641766e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: January 18, 2023
C:\Windows\Temp\g7F7E.tmp File name: g7F7E.tmp
Size: 1.72 MB (1721856 bytes)
MD5: 9ba21c15300e32df90c27c6a3d808888
Detection count: 12
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Windows\Temp\g7F7E.tmp
Group: Malware file
Last Updated: June 3, 2022
%ALLUSERSPROFILE%\Application Data\mspop.exe File name: mspop.exe
Size: 2.01 MB (2012672 bytes)
MD5: 1ea9632607d8e6ba9d605bdec71a8ef6
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: March 9, 2016
%ALLUSERSPROFILE%\service.exe File name: service.exe
Size: 1.79 MB (1792512 bytes)
MD5: 8d607c220c1f87319c0bc7da9b5f60c0
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 9, 2016
file.exe File name: file.exe
Size: 862.2 KB (862208 bytes)
MD5: 8c41658cce6316328ef4dfd60c39c790
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 2, 2016
%ALLUSERSPROFILE%\service.exe File name: service.exe
Size: 1.79 MB (1792512 bytes)
MD5: cf91f6d4e312e58953352480776b391f
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 9, 2016
<%WinDir>\<(Win32Graftor3471_Filename)>.exe. File name: <%WinDir>\<(Win32Graftor3471_Filename)>.exe.
Group: Malware file
<%AppData>\arquivo.exe File name: <%AppData>\arquivo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\msiql.exe%ALLUSERSPROFILE%\Windows Update\svrupg.exe%APPDATA%\svrupg.exe%LOCALAPPDATA%\fupdate\fupdate.exe%LOCALAPPDATA%\vfVirtualFishnet.exe%USERPROFILE%\Local Settings\Application Data\fupdate\fupdate.exeHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://fitness.poxyport.info" = AutoConfigURL" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://bashcontrolilimited.tecnologiaovh.com" = "AutoConfigUrl"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://187.109.161.62/index1.php" = "AutoConfigURL"

Additional Information

The following directories were created:
%LOCALAPPDATA%\4Adobe\4low%PROGRAMFILES%\Kilchwobigh%PROGRAMFILES(x86)%\Kilchwobigh

Related Posts

Loading...