Malware

How to remove “Graftor.122994”?

Malware Removal

The Graftor.122994 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.122994 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • A process attempted to delay the analysis task by a long amount of time.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates known Ruskill mutexes
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.wipmania.com
cmdpe.us
okhs.in
kjc.im

How to determine Graftor.122994?


File Info:

crc32: 12248503
md5: e58be9496b8e4bb1b098e7a91e47cfbd
name: E58BE9496B8E4BB1B098E7A91E47CFBD.mlw
sha1: b6b085a1efa30cf2adf5ce92814f37e0d7003a3f
sha256: 4e2c6337b3da91afb1ab652f6c6a557a31cbc44645302099a3e9d377b6a93578
sha512: 8a26eca9ad969de995337ef13c928843f9a5657e35dbb6c4969457f8029ee3c07078a71b6e50c48bed3c402469f4db20077b2bdf5d245aa1d2008d16dbfcbe17
ssdeep: 3072:KPefn3PLO9mb/Te7yf/QHOqneItqKkZwoMhTIGM4G2TT:PL+mPIyf4ZekqNYhMGlz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Automovo Automovo
InternalName: Automovo Automovo Automovo
FileVersion: 1.00
CompanyName: Automovo
LegalTrademarks: Automovo Automovo
Comments: Automovo Automovo
ProductName: Automovo
ProductVersion: 1.00
OriginalFilename: Automovo Automovo Automovo.exe

Graftor.122994 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Graftor.122994
FireEyeGeneric.mg.e58be9496b8e4bb1
Qihoo-360Win32/Trojan.938
ALYacGen:Variant.Graftor.122994
CylanceUnsafe
VIPREBackdoor.IRCBot
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Graftor.122994
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.96b8e4
CyrenW32/Trojan.EDHC-7848
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.cubt
NANO-AntivirusTrojan.Win32.Blocker.cndfot
RisingMalware.Undefined!8.C (TFE:3:nDxbWcyDMG)
Ad-AwareGen:Variant.Graftor.122994
SophosML/PE-A + Mal/VBSpag-A
ComodoMalware@#ffieumz8h9qw
F-SecureHeuristic.HEUR/AGEN.1117785
DrWebBackDoor.IRC.NgrBot.42
TrendMicroTROJ_SPNR.35LB13
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Graftor.122994 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.hed
Webrootw32.malware.gen
AviraHEUR/AGEN.1117785
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Graftor.D1E072
ZoneAlarmTrojan-Ransom.Win32.Blocker.cubt
GDataGen:Variant.Graftor.122994
CynetMalicious (score: 85)
McAfeeArtemis!E58BE9496B8E
MAXmalware (ai score=88)
VBA32TScope.Trojan.VB
PandaTrj/Genetic.gen
ESET-NOD32Win32/Dorkbot.B
TrendMicro-HouseCallTROJ_SPNR.35LB13
TencentWin32.Trojan.Blocker.Akfb
YandexTrojan.Blocker!YZNT49i2xmg
IkarusTrojan.Backdoor.SmallX
BitDefenderThetaGen:NN.ZevbaF.34590.km0@auDqYTP
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Graftor.122994?

Graftor.122994 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment