Trojan Graftor – AdvTCApp.exe – bd83c21db3a55f0dd50d931b122c67c4

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Trojan Graftor
Also known as: Backdoor Ping, Trojan Agent
SHA256: f67e64ebf80fe2c1406647d49b36b53f9429f694b281d6dc3378aad452622493
SHA1: 23ba97b86b3d55e480505d131186bf6e8f9df5f8
MD5: bd83c21db3a55f0dd50d931b122c67c4
File size: 581704 bytes

Created files:

%Program Files%\AdvTopC\AdvTCApp.exe – Trojan Graftor
%Program Files%\AdvTopC\TCCheckAgent.exe – Trojan Graftor
%Program Files%\AdvTopC\TCHelper.dll – Trojan Graftor
%Program Files%\AdvTopC\TCUnins.exe – Trojan Graftor

Trojan Graftor created autostart registry keys:

HKLM\Software\Classes\CLSID\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}\InprocServer32 : %Program Files%\AdvTopC\TCHelper.dll
HKLM\Software\Classes\CLSID\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}\InprocServer32\ThreadingModel: Apartment
HKLM\System\CurrentControlSet\Services\TCCheckAgent\Type: 10010000
HKLM\System\CurrentControlSet\Services\TCCheckAgent\Start: 02000000
HKLM\System\CurrentControlSet\Services\TCCheckAgent\DisplayName: TCCheckAgent
HKLM\System\CurrentControlSet\Services\TCCheckAgent\ImagePath: %Program Files%\AdvTopC\TCCheckAgent.exe

Leave a Reply