Home Malware Programs Trojans Graftor

Graftor

Posted: June 4, 2012

Threat Metric

Ranking: 10,378
Threat Level: 8/10
Infected PCs: 145,814
First Seen: October 13, 2011
Last Seen: February 7, 2025
OS(es) Affected: Windows

Graftor is a Trojan, which poses as a legitimate software program. Graftor attempts to connect to the internet and contact numerous remote servers without the affected PC user permission and knowledge, likely to receive instructions from the hacker, or to drop more malware threats. Graftor modifies the 'autorun' registry so that it can load automatically every time you start Windows. Graftor copies malicious executable files into its profile directory. Graftor also installs its components in the system background.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Google\GoogleUpdate.exe File name: GoogleUpdate.exe
Size: 282.62 KB (282624 bytes)
MD5: 496e0c365fe971677dbf99e62aa0208e
Detection count: 2,677
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Google
Group: Malware file
Last Updated: October 29, 2019
C:\Program Files (x86)\Kilchwobigh\klcUpd.dll File name: klcUpd.dll
Size: 328.19 KB (328192 bytes)
MD5: 94ddc69fced08a6ed5d735027e815ec4
Detection count: 2,672
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Kilchwobigh\klcUpd.dll
Group: Malware file
Last Updated: December 13, 2021
C:\Windows\Temp\04095\conhost.exe File name: conhost.exe
Size: 1.26 MB (1265152 bytes)
MD5: 60f7cb231a831ca5cda342020a5208ce
Detection count: 2,415
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\04095\conhost.exe
Group: Malware file
Last Updated: June 22, 2022
%APPDATA%\service.exe File name: service.exe
Size: 1.73 MB (1738240 bytes)
MD5: 29b4d30fc9fe15bf410632820e0e2e9d
Detection count: 742
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 4, 2016
%PROGRAMFILES%\Microsoft Data\InstallAddons.exe File name: InstallAddons.exe
Size: 636.41 KB (636416 bytes)
MD5: 8565b96e6239c5b987ec8202d6be1c16
Detection count: 480
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microsoft Data
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Microsoft\Protect\ssppsv.exe File name: ssppsv.exe
Size: 167.93 KB (167936 bytes)
MD5: bbddd30bdb03f2e23eceeaa443f62c5a
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Protect
Group: Malware file
Last Updated: August 25, 2017
%ALLUSERSPROFILE%\/service.exe File name: /service.exe
Size: 1.73 MB (1734656 bytes)
MD5: 036fde7f171d46c24f243aa8688e6e68
Detection count: 340
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\/service.exe
Group: Malware file
Last Updated: October 9, 2023
%APPDATA%\service90132.exe File name: service90132.exe
Size: 1.93 MB (1936896 bytes)
MD5: 2915096fb3ccada63b983f9c68515bc8
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 30, 2020
%SYSTEMDRIVE%\Users\<username>\959403039485030\winupd32cfg.exe File name: winupd32cfg.exe
Size: 89.48 KB (89484 bytes)
MD5: c78924cc0e6b440b5460f04f4aaf17d1
Detection count: 148
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\959403039485030\winupd32cfg.exe
Group: Malware file
Last Updated: April 27, 2022
%APPDATA%\Microsoft\Protect\ssppsvc.exe File name: ssppsvc.exe
Size: 166.91 KB (166912 bytes)
MD5: 9993e3c51b65acc306f0077ca81a1a5d
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Protect
Group: Malware file
Last Updated: August 25, 2017
dir\name.exe File name: name.exe
Size: 738.3 KB (738304 bytes)
MD5: 540f9456415ec88e2ab9f5ac635d28e7
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: dir
Group: Malware file
Last Updated: September 19, 2017
%PROGRAMFILES%\BaiduEx\uninit.exe File name: uninit.exe
Size: 560.18 KB (560186 bytes)
MD5: 885d05e1326569602be8cbfd2e16396c
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BaiduEx
Group: Malware file
Last Updated: March 23, 2016
%WINDIR%\system32\config\systemprofile\AppData\Roaming\svrupg.exe File name: svrupg.exe
Size: 2.76 MB (2767872 bytes)
MD5: f0c179316ccfc4ad54287fbb6e8b99bf
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2016
%ALLUSERSPROFILE%\msiqljp.exe File name: msiqljp.exe
Size: 46.26 KB (46260 bytes)
MD5: 0566e2efd6b6f189c2cf9a44ebc417de
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 23, 2016
%LOCALAPPDATA%\storegid\storegidup.exe File name: storegidup.exe
Size: 219.29 KB (219296 bytes)
MD5: 5952f628e42aaf4ac1b8ea477c455f14
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\storegid
Group: Malware file
Last Updated: March 22, 2016
C:\Windows\Temp\gAC93.tmp.exe File name: gAC93.tmp.exe
Size: 151.55 KB (151552 bytes)
MD5: b7f5f8489ce01c4b11ac530f24b07555
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\gAC93.tmp.exe
Group: Malware file
Last Updated: April 23, 2022
%PROGRAMFILES%\22cc3ef3650630662937132a51b94f7c\20d19e546d1f3082e70434b98145cc8c.exe File name: 20d19e546d1f3082e70434b98145cc8c.exe
Size: 818.68 KB (818688 bytes)
MD5: 26ca0dfcfde6b929d4385b6c1ba6c71f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\22cc3ef3650630662937132a51b94f7c
Group: Malware file
Last Updated: July 3, 2018
%ALLUSERSPROFILE%\msdtabc.exe File name: msdtabc.exe
Size: 1.3 MB (1308655 bytes)
MD5: 53371ed43ea4d4b1a3401fa3f641766e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: January 18, 2023
C:\Windows\Temp\g7F7E.tmp File name: g7F7E.tmp
Size: 1.72 MB (1721856 bytes)
MD5: 9ba21c15300e32df90c27c6a3d808888
Detection count: 12
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Windows\Temp\g7F7E.tmp
Group: Malware file
Last Updated: June 3, 2022
%ALLUSERSPROFILE%\Application Data\mspop.exe File name: mspop.exe
Size: 2.01 MB (2012672 bytes)
MD5: 1ea9632607d8e6ba9d605bdec71a8ef6
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: March 9, 2016
%WINDIR%\TEMP\is-UGUVS.tmp\print.exe File name: print.exe
Size: 2.96 MB (2960896 bytes)
MD5: aeefcdb175394cef5f0ffeba1b673662
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\is-UGUVS.tmp
Group: Malware file
Last Updated: March 20, 2020
%TEMP%\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe File name: adv_168.exe
Size: 2.07 MB (2073088 bytes)
MD5: ae0c649f117ef89f4e82667fac584330
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\f9626892-7a78-3199-abd2-97bbce96297b
Group: Malware file
Last Updated: June 1, 2016
<%WinDir>\<(Win32Graftor3471_Filename)>.exe. File name: <%WinDir>\<(Win32Graftor3471_Filename)>.exe.
Group: Malware file
<%AppData>\arquivo.exe File name: <%AppData>\arquivo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\msiql.exe%ALLUSERSPROFILE%\Windows Update\svrupg.exe%APPDATA%\svrupg.exe%LOCALAPPDATA%\fupdate\fupdate.exe%LOCALAPPDATA%\vfVirtualFishnet.exe%USERPROFILE%\Local Settings\Application Data\fupdate\fupdate.exeHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://fitness.poxyport.info" = AutoConfigURL" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://bashcontrolilimited.tecnologiaovh.com" = "AutoConfigUrl"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"http://187.109.161.62/index1.php" = "AutoConfigURL"

Additional Information

The following directories were created:
%LOCALAPPDATA%\4Adobe\4low%PROGRAMFILES%\Kilchwobigh%PROGRAMFILES(x86)%\Kilchwobigh

Related Posts

Loading...