Adware.Graftor

Logo_Malware
Graftor is a software usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified the 07/08/2015.

Features

– It belongs to a family of Adwares and PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional

Main Actions

– It installs a plugin of the browser Google Chrome (G2)
– It installs a program of extension for browser Mozilla Firefox (M2)
– It installs a plugin of the browser Mozilla Firefox (P2)
– It installs as a process launched at startup of the system (RP),
– It installs as a service to be launched each time the system (O23),(SS/SR).
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).

– (…) — c:Windowsfaw.exe
– (…) — c:Windowsmfaw.exe
O23 – Service: faw (faw) . (…) – c:Windowsfaw.exe
O23 – Service: mfaw (mfaw) . (…) – c:Windowsmfaw.exe
O43 – CFD: 2015/07/15 16:19:03 – [] HD — C:ProgramDatafaw
SR – Auto faw (faw) . (…) – c:Windowsfaw.exe
SR – Auto mfaw (mfaw) . (…) – c:Windowsmfaw.exe

O23 – Service: SystemSafeguard (11c3b81e) . (…) – c:Program Files (x86)SystemSafeguardSystemSafeguard.dll
O42 – Logiciel: SystemSafeguard – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fd3b02ee}
O43 – CFD: 2015/08/26 09:41:51 – [] D — C:Program Files (x86)SystemSafeguard

O23 – Service: PremiumStream (32c3c91d) . (…) – c:Program Files (x86)PremiumStreamPremiumStream.dll
O42 – Logiciel: PremiumStream – (.PremiumStream.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{d65a1a66}
O43 – CFD: 2015/08/21 09:21:51 – [] D — C:Program Files (x86)PremiumStream

O23 – Service: ContradePlatform (21d3b91f) . (…) – c:Program Files (x86)ContradePlatformContradePlatform.dll
O42 – Logiciel: ContradePlatform – (.PointerBooster.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}
O43 – CFD: 2015/08/22 05:21:52 – [] D — C:Program Files (x86)ContradePlatform

O23 – Service: EnhanceIt (31d3b91f) . (…) – c:Program Files (x86)EnhanceItEnhanceIt.dll
O42 – Logiciel: enhanceit – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{51489c1e}
O43 – CFD: 2015/07/12 05:01:02 – [] D — C:Program Files (x86)EnhanceIt

O23 – Service: CutterInstance (3c2d81f8) . (…) – c:Program Files (x86)CutterInstanceCutterInstance.dll
O42 – Logiciel: CutterInstance – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{51489c1e}
O43 – CFD: 16/01/2015 – 17:34:56 – [] —-D C:Program Files (x86)CutterInstance
SS – | Auto 22/07/1658 2198016 | (3c2d81f8) . (…) – c:Program Files (x86)CutterInstanceCutterInstance.dll

O23 – Service: UpgradeStance (8ae27094) . (…) – c:Program Files (x86)UpgradeStanceUpgradeStance.dll
O42 – Logiciel: UpgradeStance – (.PointerBooster.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}
O43 – CFD: 12/01/2015 – 07:46:02 – [] —-D C:Program Files (x86)UpgradeStance

O23 – Service: LinkInstance (10c4b81f) . (…) – c:Program Files (x86)LinkInstanceLinkInstance.dll
O42 – Logiciel: LinkInstance – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{10c3b81e}
O43 – CFD: 20/01/2015 – 07:41:28 – [] —-D C:Program Files (x86)LinkInstance
SR – | Auto 20/01/2015 2189312 | (10c3b81e) . (…) – c:Program Files (x86)LinkInstanceLinkInstance.dll

O23 – Service: LibraryInstance (1ca156e3) . (.Software Publisher.) – c:Program Files (x86)LibraryInstanceLibraryInstance.dll
O42 – Logiciel: LibraryInstance – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{1ca156e3}
O43 – CFD: 20/01/2015 – 14:47:37 – —-D C:Program Files (x86)LibraryInstance

O23 – Service: LighterGeneration (f22bc34d) . (.Software Publisher – ???.) – c:Program Files (x86)LighterGenerationLighterGeneration.dll
O42 – Logiciel: LighterGeneration – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{f22bc34d}
O43 – CFD: 22/01/2015 – 11:46:37 – —-D C:Program Files (x86)LighterGeneration

O23 – Service: PragmaGeneration (b80b68f9) . (…) – c:Program Files (x86)PragmaGenerationPragmaGeneration.dll
O42 – Logiciel: PragmaGeneration – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{b80b68f9}
O43 – CFD: 22/03/2015 – 11:47:37 – —-D C:Program Files (x86)PragmaGeneration

O23 – Service: SystemContinue O23 – Service: SystemContinue (9617fb41) . (…) – c:Program Files (x86)SystemContinueSystemContinue.dll
O42 – Logiciel: SystemContinue – (.Software Publisher.) — {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{9617fb41}
O43 – CFD: 22/02/2015 – 11:48:37 – —-D C:Program Files (x86)SystemContinue

M2 – MFEP: prefs.js [] crazylowerprice v0.3 (..)
HKLMSOFTWAREWow6432NodeSystemLifterX

Alias

Adware.Graftor
PUP.Optional.MultiPlug.PLY

Remove Software

– Remove software in Windows Configuration Panel,

Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (No Ratings Yet)
SOSVirusLoading...

Leave a Comment