Malware

How to remove “Graftor.266344”?

Malware Removal

The Graftor.266344 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.266344 virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Graftor.266344?


File Info:

crc32: 28817FFD
md5: c2f16cd429dd08bb178365955dac6ed6
name: C2F16CD429DD08BB178365955DAC6ED6.mlw
sha1: 0bb82a41e00874211a84f7cccf37802c0a629b61
sha256: 804f8e5c2de4db21a457a4c43c68a5ecb7ac40f76efb14425d7de1e6c074ac4a
sha512: 6c4c975f7798ffbdcf812349953cc858a3236b39d43b742362e4c3d2f094278091152be0e98352abb5f6488a34cbfa8845ae10c5ffc40df1753e93ade72fcc0b
ssdeep: 6144:2S5hc/u6TclZR8CL6NwygIah/scAz6+2Knfrof:2ghcm6TcbR8CHMu+tjof
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright by Software House
InternalName: setup
FileVersion: 1,0,0,0
CompanyName: Software House
LegalTrademarks: Copyright by Software House
ProductName: Installer
ProductVersion: 1,0,0,0
FileDescription: Installer
OriginalFilename: setup.exe
Translation: 0x0409 0x04e4

Graftor.266344 also known as:

K7AntiVirusUnwanted-Program ( 004dd1c01 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3968
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.266344
CylanceUnsafe
ZillyaBackdoor.AndromCRTD.Win32.201
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Sarento.8c1a692f
K7GWUnwanted-Program ( 004dd1c01 )
Cybereasonmalicious.429dd0
SymantecRansom.EncRaaS!g1
ESET-NOD32Win32/Filecoder.EZ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.266344
NANO-AntivirusTrojan.Win32.Raas.eakdru
MicroWorld-eScanGen:Variant.Graftor.266344
TencentWin32.Trojan.Falsesign.Szuv
Ad-AwareGen:Variant.Graftor.266344
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34770.CG2@ayUlQKfi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Sarento.R002C0DCL21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.c2f16cd429dd08bb
EmsisoftGen:Variant.Graftor.266344 (B)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1131979
Antiy-AVLTrojan/Generic.ASMalwS.1724B5D
MicrosoftRansom:Win32/Sarento
ArcabitTrojan.Graftor.D41068
AegisLabTrojan.Win32.Raas.toqW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.266344
AhnLab-V3Trojan/Win32.Sarento.C1344226
McAfeeArtemis!C2F16CD429DD
MAXmalware (ai score=87)
VBA32Trojan.Encoder
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Sarento.R002C0DCL21
RisingRansom.Jeiphoos!1.A3FC (CLASSIC)
YandexTrojan.GenAsa!o5O3OaPV73Y
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Carbanak.A!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxQBC4MA

How to remove Graftor.266344?

Graftor.266344 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment