Malware

Graftor.250783 removal instruction

Malware Removal

The Graftor.250783 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.250783 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
2kui.cn

How to determine Graftor.250783?


File Info:

crc32: 5EC649B3
md5: 3da9cdf16364537989f658993fd0ab25
name: 6.exe
sha1: a29302fdbbebe584ce810783a171150c80c6790e
sha256: ca17b335df63f6254566628fdfe48cf477682b5ab08854c69d196f7464397364
sha512: 9ec1c5b9061d1ab0ccdea0ee1bd840bd1e9fefd092cfe3b48a8577275593ea8254d3a12afb1727734c70bc17468ade7b24fe45e94160d155edaadd606b45297f
ssdeep: 192:k71OaDxT5YXXjIkTkYhlGp+8lGnDLps1cfzbkW6i9b3mEj0hmleL/hJFW9ey6:kZOaMskTvhl7Lps1cfzbFtrmETlelJF
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Graftor.250783 also known as:

MicroWorld-eScanGen:Variant.Graftor.250783
FireEyeGeneric.mg.3da9cdf163645379
CAT-QuickHealTrojan.Dynamer.8183
McAfeeTrojan-FJYJ!1B09D43F3C14
CylanceUnsafe
BitDefenderGen:Variant.Graftor.250783
Cybereasonmalicious.163645
TrendMicroBKDR_ZEGOST.SM22
BaiduWin32.Trojan-Downloader.Agent.cw
F-ProtW32/ServStart.F.gen!Eldorado
SymantecDownloader.Domar
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataGen:Variant.Graftor.250783
KasperskyTrojan-Downloader.Win32.Agent.wuiib
NANO-AntivirusTrojan.Win32.Agent.dxthuy
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazqe7+/tpWTVFdS9L1lzzT3B)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.250783 (B)
F-SecureTrojan.TR/Taranis.2913
DrWebTrojan.PWS.Cabal.49
ZillyaTool.Inject.Win32.3332
McAfee-GW-EditionBehavesLike.Win32.Mydoom.lh
Trapminesuspicious.low.ml.score
IkarusTrojan-Downloader.Win32.Agent
JiangminTrojan.ServStart.aa
WebrootW32.Trojan.Gen
AviraTR/Taranis.2913
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Graftor.D3D39F
ZoneAlarmTrojan-Downloader.Win32.Agent.wuiib
TACHYONTrojan-Downloader/W32.Agent.19456.EM
AhnLab-V3Malware/Win32.Generic.C1145108
BitDefenderThetaGen:NN.ZexaF.34126.amGfamrWDofb
ALYacGen:Variant.Graftor.250783
MAXmalware (ai score=80)
VBA32BScope.Trojan.ServStart
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.BOW
TrendMicro-HouseCallBKDR_ZEGOST.SM22
TencentMalware.Win32.Gencirc.10b3ee8d
YandexTrojan.DL.Agent!AR39btbxatQ
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.BNA!tr
Ad-AwareGen:Variant.Graftor.250783
AVGWin32:Evo-gen [Susp]
Qihoo-360Win32/Trojan.Downloader.b89

How to remove Graftor.250783?

Graftor.250783 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment