Trojan Graftor – services.exe – 644a77870a90a8e58d5a32a6000d2164

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Graftor
Also known as: Trojan Agent, Trojan Swisyn
SHA256: b4ca80448003a21c42a7f249cbb64c19a83548fe136d476887b7cfffca19f4c4
SHA1: 407262d56cd969cb0ba5bc1d4376ba8d9c17d5ef
MD5: 644a77870a90a8e58d5a32a6000d2164
File size: 162816 bytes

Created files:

%Program Files Common%\Tencent\services.exe – Trojan Graftor
%Program Files Common%\Tencent\tuziboyAuTo.dll – Trojan Graftor
%Program Files Common%\Tencent\tuziboyAuTo.ocx – Trojan Graftor
%Program Files Common%\Tencent\tuziboyDw.ocx – Trojan Graftor

Trojan Graftor created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ttplay: %Program Files Common%\Tencent\services.exe
HKLM\System\CurrentControlSet\Services\diskmanager\Type: 10000000
HKLM\System\CurrentControlSet\Services\diskmanager\Start: 02000000
HKLM\System\CurrentControlSet\Services\diskmanager\DisplayName: windows Disk Manager
HKLM\System\CurrentControlSet\Services\diskmanager\ImagePath: %Program Files Common%\Tencent\tuziboyAuTo.dll

Leave a Reply