Malware

Should I remove “Graftor.296973 (B)”?

Malware Removal

The Graftor.296973 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.296973 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.296973 (B)?


File Info:

name: 755FB7EC44D34AD9D407.mlw
path: /opt/CAPEv2/storage/binaries/d541de0dab32ae47d7bae848ce61deafd81565d1164b5cf7644116cfcc492586
crc32: 4C8CF77A
md5: 755fb7ec44d34ad9d407e0592c1ea6b8
sha1: c2063eaf0c4992b58f2e94baed1803d4b6fbbef7
sha256: d541de0dab32ae47d7bae848ce61deafd81565d1164b5cf7644116cfcc492586
sha512: f0839e82aa6e4d88473146dcec8ef23346efe9a8e5f71785d94f5cc6c8d61802d007f2ca5d89877cd3d185513fbf6e6e2f3cfbab8d7f3c12d02efd5ede6b811f
ssdeep: 3072:qSdeRYcgVbtK4PBcMs3t9RFFHA44WXB+F6UYM9iPS4JHmS:qeTVb97s1F+4n+F6iAGS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6D312294754588FEBB876F439FED01BBC43F0C8148B451B7C6B99992A7A6C40EC9C0E
sha3_384: a5cde3a980804ccddc7a5be9628376e35f3a7e174e1dd491e07a48a3286abb07d5a0a7350f18c669eb8270f57ca06156
ep_bytes: 60be00a041008dbe0070feff5783cdff
timestamp: 2005-02-15 18:32:34

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 3.80
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2008
OriginalFilename: WinRAR.exe
Comments: Translation © Dmitry Yerokhin 1999-2008

Graftor.296973 (B) also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Diple.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.296973
FireEyeGeneric.mg.755fb7ec44d34ad9
ALYacGen:Variant.Graftor.296973
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1135669
SangforTrojan.Win32.Dropper.Gen
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanPSW:Win32/Kryptik.839669b1
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.c44d34
VirITTrojan.Win32.Panda.VB
CyrenW32/S-301e7fab!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.KND
APEXMalicious
ClamAVWin.Trojan.Downloader-18927
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.296973
NANO-AntivirusTrojan.Win32.Diple.iuiqx
ViRobotTrojan.Win32.A.Zbot.140016[UPX]
TencentWin32.Trojan.Falsesign.Aglj
Ad-AwareGen:Variant.Graftor.296973
EmsisoftGen:Variant.Graftor.296973 (B)
ComodoMalware@#a1ujclumtn1s
DrWebTrojan.PWS.Panda.547
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-S + Mal/FakeAV-BW
IkarusTrojan-Spy.Win32.SpyEyes
GDataGen:Variant.Graftor.296973
JiangminTrojanSpy.Zbot.cedn
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
SUPERAntiSpywareTrojan.Agent/Gen-Pervaser
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot.gen!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4017
Acronissuspicious
McAfeeArtemis!755FB7EC44D3
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
PandaBck/Qbot.AO
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingExploit.ShellCode!8.2A (CLOUD)
YandexTrojan.GenAsa!zLGfEEkWneo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1963355.susgen
FortinetW32/Kryptik.NAS!tr
BitDefenderThetaGen:NN.ZexaF.34212.imLfaiWByRfc
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.296973 (B)?

Graftor.296973 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment