Solved! Use LDAPI32.EXE (Trojan Graftor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

LDAPI32.EXE – Trojan Graftor removal

FileMD5Virus Alias
LDAPI32.EXE cc0ab72b6e752d71f95282a9520bdff6 Trojan Graftor
LDAPI32.EXE cc0ab72b6e752d71f95282a9520bdff6 Trojan Generic
LDAPI32.EXE cc0ab72b6e752d71f95282a9520bdff6 Trojan Agent
LDAPI32.EXE cc0ab72b6e752d71f95282a9520bdff6 Trojan Small

LDAPI32.EXE size: 16896 bytes
LDAPI32.EXE hash: CC0AB72B6E752D71F95282A9520BDFF6

Created files:

%SysDir%\ldapi32.exe
%SysDir%\ntcvx32.dll
%SysDir%\ntswrl32.dll
%SysDir%\vssms32.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\vssms32: %WinDir%\System32\vssms32.exe

Detected by UnHackMe:

LDAPI32.EXE
Default location: %SYSDIR%\LDAPI32.EXE

Dropper information:
MD5: 56f5c0c5f24892e5657bcd01642e7fe9
File size: 747520 bytes

Leave a Reply