Malware

What is “Graftor.289890”?

Malware Removal

The Graftor.289890 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.289890 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Graftor.289890?


File Info:

crc32: F75276F6
md5: c3b8f978f79f884d786e6b0e70cf88ad
name: C3B8F978F79F884D786E6B0E70CF88AD.mlw
sha1: bc3f41c73610cc95779e23624cbd52bfb49bfb19
sha256: 5ed7da395cb77bc09a85a7f87ff91dd0e2ce4a4473af4d92cf99ec237d95ce76
sha512: d2723675168401f24887268f32c2f67d46968cfcfb7080e5b0a21fe30f169aed89f0c3aee1c78548fac502d94671b2c4744611c576ad8334ba695d25bd3f6487
ssdeep: 12288:C6P0tYqUQ/2B8oO3vDKmhAB0sh4q0Uhs8iMTecD1dIlrJ/kIQbOMWG8LdmBKSDB:C6stYqUbAvDKmzDU2V70bO5LdmU4O2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2015 Symantec Corporation. All rights reserved.
InternalName: Norton Security
FileVersion: 22.5.4.24
CompanyName: Symantec Corporation
Product Date: 9/18/2015
ProductName: Norton Security
ProductVersion: 22.5.4.24
FileDescription: Norton Security
OriginalFilename: NS_GenericDef.exe
Translation: 0x0409 0x04b0

Graftor.289890 also known as:

K7AntiVirusTrojan-Downloader ( 0055e3da1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.1092
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.289890
CylanceUnsafe
ZillyaDownloader.Agent.Win32.308820
SangforTrojan.Win32.Agent.atgen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Zlob.180910
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.8f79f8
BaiduWin32.Trojan-Downloader.Agent.bh
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.BXR
APEXMalicious
AvastFileRepMalware
ClamAVWin.Dropper.Gh0stRAT-9497868-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.289890
NANO-AntivirusTrojan.Win32.Agent.dyzqux
MicroWorld-eScanGen:Variant.Graftor.289890
TencentMalware.Win32.Gencirc.11492a17
Ad-AwareGen:Variant.Graftor.289890
SophosMal/Generic-S
ComodoMalware@#24clw2cjkofcj
BitDefenderThetaGen:NN.ZexaF.34236.UmLfae5IZrqP
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM22
McAfee-GW-EditionGenericRXFW-UF!C39A7AC7A232
FireEyeGeneric.mg.c3b8f978f79f884d
EmsisoftGen:Variant.Graftor.289890 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.glcn
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1101570
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.1F3
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Graftor.289890
AhnLab-V3Malware/Win32.Generic.C1122852
McAfeeArtemis!C3B8F978F79F
MAXmalware (ai score=99)
VBA32BScope.Backdoor.Farfli
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM22
YandexTrojan.GenAsa!G3ARxB1zZJY
FortinetW32/Agent.BNA!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Graftor.289890?

Graftor.289890 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment