Malware

What is “Graftor.293697”?

Malware Removal

The Graftor.293697 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.293697 virus can do?

  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

item.taobao.com
ocsp.globalsign.com
ocsp2.globalsign.com
crl.globalsign.com

How to determine Graftor.293697?


File Info:

crc32: C9B63197
md5: c301e769fc8a6f626b67324b76e3a7a5
name: C301E769FC8A6F626B67324B76E3A7A5.mlw
sha1: dc76a0080fa5fe19445d6488e802b36e74c498e2
sha256: 1e62598a8e885f3971a4343e25dca14733db3a90ac59aa0cd56903106f641353
sha512: 542275de6a750460cce2c9a0d9712acf1d2b49c81795acc86489a851126f5e169c829bd31c46a66904722e4836a10258ed27dd5d48596b50d068c1fcac47886d
ssdeep: 49152:UV8CmOUQrv6nMtvC65Is58q+yaKo6aB5fW:O8IUQT6nS5ICDqLE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: builder x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: builder
Comments: builder
ProductName: builder
ProductVersion: 1.0.0.0
FileDescription: builder
Translation: 0x0804 0x04b0

Graftor.293697 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.293697
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDropper:Win32/Black.39eb4db7
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.9fc8a6
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Patched-ANW [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Graftor.293697
NANO-AntivirusTrojan.Win32.Black.dbdcvz
MicroWorld-eScanGen:Variant.Graftor.293697
TencentWin32.Trojan.Suspicious.Sumz
Ad-AwareGen:Variant.Graftor.293697
SophosGeneric PUA NM (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34266.3r0@a0Nwt4db
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.c301e769fc8a6f62
EmsisoftGen:Variant.Graftor.293697 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Black.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.A6B804
MicrosoftVirTool:Win32/Obfuscator.XZ
GDataWin32.Trojan.PSE.11B5R9D
Acronissuspicious
McAfeeGenericRXER-EL!C301E769FC8A
MAXmalware (ai score=82)
VBA32BScope.Adware.Presenoker
MalwarebytesTrojan.MalPack.FlyStudio
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazrcRTSVPX4SPENMP8va5n7w)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Patched-ANW [Trj]

How to remove Graftor.293697?

Graftor.293697 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment