Malware

Graftor.16340 malicious file

Malware Removal

The Graftor.16340 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.16340 virus can do?

  • Loads a driver
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Graftor.16340?


File Info:

crc32: 8B1F42A4
md5: c1297a00ced06df89647ab1b8495c511
name: C1297A00CED06DF89647AB1B8495C511.mlw
sha1: cc325513ab6447e4cb9a0f47fdb5a9bfb1c4722e
sha256: 5fc82dbd9b7e107a7accd1d5b22de51eaf7519e4b59350c02d4545bf007f9e7e
sha512: c96ed3f18fcbe025d441fd1a771d2819f384bce01f1354d2b615cf7fced712c0405fa11d843f929dddd762f2ff4c75164aee50a2cc35aa60305bf62587a5dca7
ssdeep: 24576:bt+eudigKcZRql1t0yq8tTU8yM6jGboZuIzyaku:bkVdTmTs868l+9vmRu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright by Dianro[Butterfly Fairy]
FileVersion: 1.0.0.0
CompanyName: Dianro
Comments: Anrox7cfbx5217[qqt321.cn]
ProductName: Anro Soft
ProductVersion: 1.0.0.0
FileDescription: QQx58024.3x7ec8x7ed3x8005
Translation: 0x0804 0x04b0

Graftor.16340 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.Genome.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.15999
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.16340
CylanceUnsafe
ZillyaTrojan.Genome.Win32.156429
SangforSuspicious.Win32.Ulise.94931
AlibabaRiskWare:Win32/ProcPatcher.6660bba6
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.0ced06
BaiduWin32.Rootkit.Agent.f
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:MiscX-gen [PUP]
ClamAVWin.Malware.Flystudio-9877903-0
Kasperskynot-a-virus:UDS:RiskTool.Win32.ProcPatcher.a
BitDefenderGen:Variant.Graftor.16340
NANO-AntivirusTrojan.Win32.TrjGen.cuylrq
MicroWorld-eScanGen:Variant.Graftor.16340
Ad-AwareGen:Variant.Graftor.16340
SophosGeneric PUA MM (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXNF-VT!C1297A00CED0
FireEyeGeneric.mg.c1297a00ced06df8
EmsisoftGen:Variant.Graftor.16340 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.biga
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.21F11E
KingsoftWin32.Troj.Genome.(kcloud)
MicrosoftTrojan:Win32/Dynamer!dtc
GDataWin32.Trojan.PSE.11B5R9D
Acronissuspicious
McAfeeGenericRXNF-VT!C1297A00CED0
MAXmalware (ai score=99)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/CI.A
RisingRootkit.Agent!1.6784 (CLASSIC)
YandexTrojan.Agent!YKTmHu1qv4s
IkarusTrojan.Agent3
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:MiscX-gen [PUP]
Paloaltogeneric.ml

How to remove Graftor.16340?

Graftor.16340 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment