Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.AppGraffiti.A

PUP.AppGraffiti.A

Posted: September 30, 2013

Threat Metric

Ranking: 7,915
Threat Level: 1/10
Infected PCs: 105,139
First Seen: September 30, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

PUP.AppGraffiti.A is a potentially unwanted application, which may contain adware capabilities, add relevant toolbars or have other uncertain goals. PUP.AppGraffiti.A is not a PC infection, but it may carry numerous destructive capabilities. PUP.AppGraffiti.A may use deceptive tactics to boost traffic of a specific commercial website and make a profit from sponsored links or other pay-per-click methods. PUP.AppGraffiti.A may enter the PC packaged with freeware and shareware programs (video recording/streaming, download-managers or PDF creators). PUP.AppGraffiti.A may also be packed within the custom installer on many dubious download websites, so if the web user has downloaded a certain software product from these download websites, he might have also downloaded and installed PUP.AppGraffiti.A through the setup process of another software product.

Aliases

Trj/CI.A [Panda]Crypt_s.ATD [AVG]Trojan.Crypt_s [Ikarus]Dropper/Win32.Clons [AhnLab-V3]Trojan:Win32/Boaxxe.E [Microsoft]TROJ_GEN.RCBCDER13 [TrendMicro]TR/Crypt.TPM.Gen [AntiVir]Gen:Variant.Symmi.8961 [F-Secure]Backdoor.Win32.Agent.SPA [Comodo]Gen:Variant.Symmi.15820 [BitDefender]W32/Boaxxe.F.gen!Eldorado [F-Prot]Trojan [K7AntiVirus]Sefnit-FBKE!0FFA7A08B108 [McAfee](Suspicious) - DNAScan [CAT-QuickHeal]Trj/Genetic.gen [Panda]
More aliases (31)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\aaaaaa\Limpieza\backups\backup-20120927-184422-270.dll File name: backup-20120927-184422-270.dll
Size: 271.04 KB (271048 bytes)
MD5: 72e41ed4f6420cb4e28b9b4e7170eaa5
Detection count: 169
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\aaaaaa\Limpieza\backups\backup-20120927-184422-270.dll
Group: Malware file
Last Updated: December 16, 2024
C:\System Volume Information\_restore{567CE13D-4317-4500-BC34-7FB345E09232}\RP1555\A0352771.dll File name: A0352771.dll
Size: 271.08 KB (271080 bytes)
MD5: 95d55bf27c6164595ed6b1cd0384afbc
Detection count: 131
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\System Volume Information\_restore{567CE13D-4317-4500-BC34-7FB345E09232}\RP1555\A0352771.dll
Group: Malware file
Last Updated: May 13, 2021
%LOCALAPPDATA%\AppGraffiti\ifuwdnkl.dll File name: ifuwdnkl.dll
Size: 600.57 KB (600576 bytes)
MD5: e965964eb330dc665990533c7415a066
Detection count: 85
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%LOCALAPPDATA%\AppGraffiti\DrawLine.dll File name: DrawLine.dll
Size: 809.47 KB (809472 bytes)
MD5: 3b73160927fc61d3b7494d5f2a3a42a8
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%LOCALAPPDATA%\AppGraffiti\MSRD3X40.dll File name: MSRD3X40.dll
Size: 483.32 KB (483328 bytes)
MD5: 0e442001e7bce9dca9314e05d707a77b
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
C:\Program Files (x86)\AppGraffiti\unins000.exe File name: unins000.exe
Size: 1.22 MB (1223040 bytes)
MD5: d8b071af0eed83c5344413e6a67944b2
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\AppGraffiti\unins000.exe
Group: Malware file
Last Updated: June 16, 2023
%LOCALAPPDATA%\AppGraffiti\aigtewbe.dll File name: aigtewbe.dll
Size: 762.88 KB (762880 bytes)
MD5: f577aab3e2001644a5188418d90eb60b
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%TEMP%\AppGraffiti_Temp\AppGraffiti.jar File name: AppGraffiti.jar
Size: 8.77 KB (8777 bytes)
MD5: 91f4a32b3d0aa636bf068e6e371ac605
Detection count: 30
Mime Type: unknown/jar
Path: %TEMP%\AppGraffiti_Temp
Group: Malware file
Last Updated: November 2, 2022
%LOCALAPPDATA%\AppGraffiti\uzqbsgtt.dll File name: uzqbsgtt.dll
Size: 335.87 KB (335872 bytes)
MD5: 7efb6d3c63893a5f226e502446eb50ae
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%PROGRAMFILES(x86)%\AppGraffiti\AppGraffiti64.dll File name: AppGraffiti64.dll
Size: 1.66 MB (1665192 bytes)
MD5: 3d42d90a78a57018ecce76953ae46d2e
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\AppGraffiti
Group: Malware file
Last Updated: June 17, 2014
C:\System Volume Information\_restore{567CE13D-4317-4500-BC34-7FB345E09232}\RP1574\A0356392.dll File name: A0356392.dll
Size: 271.52 KB (271528 bytes)
MD5: 13b75bfbd2a09219cbcd8055bef3cafe
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\System Volume Information\_restore{567CE13D-4317-4500-BC34-7FB345E09232}\RP1574\A0356392.dll
Group: Malware file
Last Updated: May 13, 2021
%PROGRAMFILES%\AppGraffiti\AppGraffiti.dll File name: AppGraffiti.dll
Size: 1.03 MB (1038504 bytes)
MD5: 19d792d5b9af2ecef930b66d6eb91dc7
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\AppGraffiti
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES%\AppGraffiti\AGupdate.exe File name: AGupdate.exe
Size: 894.04 KB (894048 bytes)
MD5: 97df49f05d706a713fc32905db1727f4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\AppGraffiti
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\AppGraffiti\is-2TIBH.tmp File name: is-2TIBH.tmp
Size: 269.51 KB (269512 bytes)
MD5: 91d3e76a4c8ad71c0b1ebb1ba6c0a909
Detection count: 7
File type: Temporary File
Mime Type: unknown/tmp
Path: %PROGRAMFILES(x86)%\AppGraffiti
Group: Malware file
Last Updated: August 16, 2020
%LOCALAPPDATA%\AppGraffiti\brodrhzb.dll File name: brodrhzb.dll
Size: 772.09 KB (772096 bytes)
MD5: 0ffa7a08b1080cce7a3537aafe603804
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
C:\AdwCleaner\Quarantine\C\Program Files (x86)\AppGraffiti\AppGraffiti._dll.vir File name: AppGraffiti._dll.vir
Size: 273.57 KB (273576 bytes)
MD5: 24c60b10d237c43110f10f5679cce1f1
Detection count: 7
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\AppGraffiti\AppGraffiti._dll.vir
Group: Malware file
Last Updated: October 2, 2022
%LOCALAPPDATA%\AppGraffiti\ggcorvvb.dll File name: ggcorvvb.dll
Size: 814.59 KB (814592 bytes)
MD5: a0d17ea45383fec19a0dcfd46c8b7b73
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%LOCALAPPDATA%\AppGraffiti\MSSp3fr.dll File name: MSSp3fr.dll
Size: 544.25 KB (544256 bytes)
MD5: c8070a32b189a51374ab3d3318bef026
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\AppGraffiti
Group: Malware file
Last Updated: June 18, 2014
%USERPROFILE%\Desktop\AppGraffitiSetup.exe File name: AppGraffitiSetup.exe
Size: 1.34 MB (1341808 bytes)
MD5: e9442eeb0f6730ec49345f35a205b884
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: June 18, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{022C9F90-2E96-47D6-A971-107650154563}{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}{CC99A798-FD3D-4AB4-969E-6071612524F9}{DB02BC6B-B0F0-4074-99E6-884B70FCB6AE}HKEY..\..\..\..{RegistryKeys}SOFTWARE\AppGraffitiSOFTWARE\Classes\AppGraffiti.AppGraffitiJSSoftware\Microsoft\Internet Explorer\Approved Extensions\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECCA77AD-EF06-4650-B6FC-7A0E90687EB4}SOFTWARE\Microsoft\Tracing\AppGraffiti_RASAPI32SOFTWARE\Microsoft\Tracing\AppGraffiti_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}SOFTWARE\Wow6432Node\AppGraffitiSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECCA77AD-EF06-4650-B6FC-7A0E90687EB4}SOFTWARE\Wow6432Node\Microsoft\Tracing\AppGraffiti_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\AppGraffiti_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\AppGraffiti%ALLUSERSPROFILE%\Start Menu\Programs\AppGraffiti%APPDATA%\AppGraffiti%PROGRAMFILES%\AppGraffiti%PROGRAMFILES(x86)%\AppGraffiti%USERPROFILE%\AppData\LocalLow\AppGraffiti
Loading...