Malware

Graftor.291507 information

Malware Removal

The Graftor.291507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.291507 virus can do?

  • Executable code extraction
  • Performs some HTTP requests
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Graftor.291507?


File Info:

crc32: 03AD0B76
md5: b072ebf720672affc9f9485187f1d581
name: B072EBF720672AFFC9F9485187F1D581.mlw
sha1: d675ea98c8f7840362cbea2fc2f5e92d2ac92eaa
sha256: 5f3bc30d7b1dcd080926f3d02ab9d6a463c28b20fa87fb5ea6cc1b4296ccf7f2
sha512: 70242150f79495cbb6693c83bfe071ff500b0c3e7f74613c13ad24f3c5cbc86eeb3b9d1dde9ac08680a3355d8033b13684df82784d005129dfcb2f8327019983
ssdeep: 6144:ZeFuiN8vppF8JqR+bE2kuUQTK6TD5c6K2vbJ0z2yHprM8PVySiJItXd:0MiVoR8V9K2TJ0z2yHewVySiJIdd
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: (C) Fieldtech Inc.
InternalName: setup
FileVersion: 8,5,3,2
CompanyName: Fieldtech Inc.
LegalTrademarks: (C) Fieldtech Inc.
ProductName: Install
ProductVersion: 1,2,3,1
FileDescription: Install
OriginalFilename: setup.exe
Translation: 0x0407 0x04b0

Graftor.291507 also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Crypmod.j!c
DrWebTrojan.Encoder.4901
CAT-QuickHealRansomware.Sarento.A8
ALYacGen:Variant.Graftor.291507
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.720672
SymantecRansom.EncRaaS!g2
ESET-NOD32a variant of Win32/Filecoder.EZ
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Crypmod.xvw
BitDefenderGen:Variant.Graftor.291507
NANO-AntivirusTrojan.Win32.Crypmod.fcgirj
MicroWorld-eScanGen:Variant.Graftor.291507
TencentWin32.Trojan.Crypmod.Pdbu
Ad-AwareGen:Variant.Graftor.291507
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.vG0@a0T41Bqi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPRAAS.SMA1
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.b072ebf720672aff
EmsisoftGen:Variant.Graftor.291507 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crypmod.ea
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1118560
Antiy-AVLTrojan/Generic.ASMalwS.1955CF1
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Sarento.A
GDataGen:Variant.Graftor.291507
TACHYONRansom/W32.Crypmod.346112
AhnLab-V3Malware/Win32.Generic.C1477206
McAfeeArtemis!B072EBF72067
MAXmalware (ai score=87)
VBA32BScope.Adware.NSIS.Zaitu
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPRAAS.SMA1
RisingTrojan.Generic@ML.90 (RDML:IVLpcM2gNL7zOwc9ZuY0tQ)
YandexTrojan.GenAsa!p0JpbI7yYIg
IkarusTrojan.Win32.Filecoder
FortinetW32/Crypmod.XRL!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Graftor.291507?

Graftor.291507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment