GOTOP.EXE – Trojan Graftor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

GOTOP.EXE – Trojan Graftor removal

File MD5 Virus Alias
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan Graftor
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan SuspiciousFile
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan Artemis
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan Generic
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan Click
GOTOP.EXE 32555b09ff013251631dc8bfbf9ed45c Trojan CI

GOTOP.EXE size: 2800640 bytes
GOTOP.EXE hash: 32555B09FF013251631DC8BFBF9ED45C

Created files:

%Program Files%\drivers\browser\appdata\addons.sqlite
%Program Files%\drivers\browser\appdata\Cache\_CACHE_001_
%Program Files%\drivers\browser\appdata\Cache\_CACHE_002_
%Program Files%\drivers\browser\appdata\Cache\_CACHE_003_
%Program Files%\drivers\browser\appdata\Cache\_CACHE_MAP_
%Program Files%\drivers\browser\appdata\chromeappsstore.sqlite
%Program Files%\drivers\browser\appdata\content-prefs.sqlite
%Program Files%\drivers\browser\appdata\cookies.sqlite
%Program Files%\drivers\browser\appdata\downloads.sqlite
%Program Files%\drivers\browser\appdata\extensions.sqlite
%Program Files%\drivers\browser\appdata\formhistory.sqlite
%Program Files%\drivers\browser\appdata\OfflineCache\index.sqlite
%Program Files%\drivers\browser\appdata\permissions.sqlite
%Program Files%\drivers\browser\appdata\places.sqlite
%Program Files%\drivers\browser\appdata\search.json
%Program Files%\drivers\browser\appdata\search.sqlite
%Program Files%\drivers\browser\appdata\signons.sqlite
%Program Files%\drivers\browser\appdata\startupCache\startupCache.4.little
%Program Files%\drivers\browser\appdata\urlclassifier.pset
%Program Files%\drivers\browser\appdata\urlclassifier3.sqlite
%Program Files%\drivers\browser\appdata\webappsstore.sqlite
%Program Files%\drivers\browser\chrome\browser\content\browser\aboutHome.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\aboutPrivateBrowsing.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\aboutRobots.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\aboutSessionRestore.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\certerror\aboutCertError.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\feeds\subscribe.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\fullscreen-video.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\NetworkPanel.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\safebrowsing\blockedSite.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\syncKey.xhtml
%Program Files%\drivers\browser\chrome\browser\content\browser\syncProgress.xhtml
%Program Files%\drivers\browser\chrome\browser\skin\classic\aero\browser\keyhole-forward-mask.svg
%Program Files%\drivers\browser\chrome\browser\skin\classic\browser\keyhole-forward-mask.svg
%Program Files%\drivers\GoTop.exe
%Program Files%\drivers\msvcp90.dll
%Program Files%\drivers\msvcr90.dll

Detected by UnHackMe:

GOTOP.EXE
Default location: %PROGRAM FILES%\DRIVERS\GOTOP.EXE

Dropper information:
MD5: 00bb151a6c96cd39dabd180abfd2e43d
File size: 14311762 bytes

Leave a Reply