Malware

Graftor.128860 removal tips

Malware Removal

The Graftor.128860 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.128860 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

Related domains:

dns.stressfrei-clan.de

How to determine Graftor.128860?


File Info:

name: F34C42C162B7CC3DDCA5.mlw
path: /opt/CAPEv2/storage/binaries/3159bc0d407af560213cfabeb3b7e8407d1eb2b1d4670abbe3bf630e6e68d9cf
crc32: 26EC776B
md5: f34c42c162b7cc3ddca54b569e4d920a
sha1: 64ed097703c024efc1f6caa051979a6767d79d23
sha256: 3159bc0d407af560213cfabeb3b7e8407d1eb2b1d4670abbe3bf630e6e68d9cf
sha512: 73a52b77c59b2ed3555534d8e8aa389615c7635dd79dde4a2a5aa808489f62348797d64329bb49f71f547974bb14acbbcd35c94b301e0bbb21513d73ab88a52e
ssdeep: 12288:rmtZVh9plxN51BdJFRtZVh9plxN51BdJFR9tZVh9pllxN51BdJFRtZVh9plxN516:vuSBoznA2p4T8EvhWZvfNL2qZWEtq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3E4AE21F3C38537D5631A38AC1B66D959397F202AA86C8B7BF41E4C9F34681391A3D7
sha3_384: 523a9257fd113f8e873620d4d9c0fee974b984baef662d98cafd90c5b0a32e646a873ad0da8aaf8f982d4a8978a66507
ep_bytes: 558becb9060000006a006a004975f951
timestamp: 2014-06-03 20:45:35

Version Info:

0: [No Data]

Graftor.128860 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Nosrawec.S363419
ALYacGen:Variant.Graftor.128860
MalwarebytesBackdoor.PasswordStealer
ZillyaTrojan.SchwarzeSonne.Win32.319
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.162b7c
CyrenW32/Trojan.GLVW-3608
SymantecSMG.Heur!gen
ESET-NOD32Win32/SchwarzeSonne.B
APEXMalicious
ClamAVWin.Malware.Schwarzesonne-6824322-0
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
BitDefenderGen:Variant.Graftor.128860
NANO-AntivirusTrojan.Win32.SchwarzeSonne.daisiu
MicroWorld-eScanGen:Variant.Graftor.128860
AvastWin32:Nosrawec-A [Spy]
RisingBackdoor.Win32.Nosrawec.a (CLASSIC)
Ad-AwareGen:Variant.Graftor.128860
EmsisoftGen:Variant.Graftor.128860 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.MulDrop5.32960
TrendMicroBKDR_NOSRAWEC.SMJ0
McAfee-GW-EditionBehavesLike.Win32.Sytro.jh
FireEyeGeneric.mg.f34c42c162b7cc3d
SophosML/PE-A + Mal/DelfInj-A
IkarusTrojan.Agent
GDataWin32.Backdoor.Agent.ASU
JiangminTrojanDropper.Agent.bqzo
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.A4364F
ArcabitTrojan.Graftor.D1F75C
MicrosoftBackdoor:Win32/Nosrawec.A
TACHYONTrojan-Spy/W32.DP-Recam.693248
AhnLab-V3Spyware/Win.Recam.R448762
Acronissuspicious
McAfeeGenericRXEQ-YO!F34C42C162B7
MAXmalware (ai score=89)
VBA32BScope.Trojan.Sabsik.FL
CylanceUnsafe
TrendMicro-HouseCallBKDR_NOSRAWEC.SMJ0
TencentMalware.Win32.Gencirc.10b22c02
SentinelOneStatic AI – Malicious PE
FortinetW32/SchwarzeSonne.B!tr
BitDefenderThetaAI:Packer.01152FC821
AVGWin32:Nosrawec-A [Spy]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Graftor.128860?

Graftor.128860 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment