Malware

Graftor.214259 removal guide

Malware Removal

The Graftor.214259 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.214259 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.214259?


File Info:

crc32: 12AC830C
md5: 3b32b41cda3789e1db371d9ffdc49f9c
name: 3B32B41CDA3789E1DB371D9FFDC49F9C.mlw
sha1: cec6393dff70e42d6068614fa9e4f2d71e034715
sha256: 9022a836bf4dd7dfd98d7076da22da0a6745cc66aa24b610ac4df21c464573de
sha512: fae5f7e1d5ab61ab0cc94fcc1ebb4e793279797588173bf811c7080969f42620dd3ba585af3d60e5d2aa741f0783e17343c99bed1a9cabfa41550eecb3ed3cc7
ssdeep: 24576:ASNNImh6pQxVHFOh+cAHmuZlOeXqDBPb:AQNXx2+HmXeXqDR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2014 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.04
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2014 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.04
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Graftor.214259 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Graftor.214259
FireEyeGeneric.mg.3b32b41cda3789e1
CAT-QuickHealTrojan.Bulta.RF5
ALYacGen:Variant.Graftor.214259
CylanceUnsafe
ZillyaDownloader.Banload.Win32.64763
SangforMalware
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderGen:Variant.Graftor.214259
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.cda378
BitDefenderThetaGen:NN.ZexaF.34804.pv0@aq8MzZei
CyrenW32/Trojan.FSBV-2391
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Banload.cwxz
AlibabaTrojanDownloader:Win32/Banload.2f48c745
NANO-AntivirusTrojan.Win32.Banload.dufuby
Ad-AwareGen:Variant.Graftor.214259
EmsisoftGen:Variant.Graftor.214259 (B)
ComodoApplication.Win32.LoadMoney.BFA@6bdn2a
F-SecureHeuristic.HEUR/AGEN.1121491
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GLE20
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosMal/Generic-S
IkarusWorm.Win32.Kasidet
JiangminTrojanSpy.Carberp.eut
AviraHEUR/AGEN.1121491
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Bulta!rfn
ArcabitTrojan.Graftor.D344F3
ZoneAlarmTrojan-Downloader.Win32.Banload.cwxz
GDataWin32.Trojan.Kryptik.BY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gen
Acronissuspicious
McAfeeArtemis!3B32B41CDA37
MAXmalware (ai score=82)
VBA32TrojanDownloader.Banload
MalwarebytesMalware.Heuristic.1008
PandaTrj/Chgt.O
ESET-NOD32Win32/TrojanDownloader.Banload.UKZ
TrendMicro-HouseCallTROJ_GEN.R002C0GLE20
RisingDownloader.Banload!8.15B (CLOUD)
YandexTrojan.DL.Banload!o/3M22oPLsg
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Downloader
FortinetW32/Kryptik.EIYT!tr
WebrootW32.Trojan.GenKD
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.Malware.Gen

How to remove Graftor.214259?

Graftor.214259 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment