Malware

How to remove “Graftor.296973”?

Malware Removal

The Graftor.296973 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.296973 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Likely virus infection of existing system binary
  • Attempts to identify installed analysis tools by a known file location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Graftor.296973?


File Info:

name: 7AF9D4E2C52149C41477.mlw
path: /opt/CAPEv2/storage/binaries/e9830a85719041ef9e4b170c8365642fa79a076589553daadf345cc018c85c3b
crc32: 473F9581
md5: 7af9d4e2c52149c41477165f12328575
sha1: 40556b2863ad42b6aec556ffb2f68f8042d2a234
sha256: e9830a85719041ef9e4b170c8365642fa79a076589553daadf345cc018c85c3b
sha512: 01d7374c9361b6cb0759ffee30012ac6debe361535785033a9d27451a15b6e12481d9c3b0f1538fc1d8012525b907dfd4b2a47de94e9d805e5c4eaea80fbb922
ssdeep: 6144:Gaz/gGFMAZSnX8EWKajfilkRP6PVGhzS/ZNyKWci:R986jPsPO2/ZNyKBi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151B4125A3284075FC7D74B35AC62B33B46ED79190AF4C7090F84A6472E235DA9363B53
sha3_384: 24478de7eb316f3f99e9c574ba6bc2dd24e27c61d3c4521d402d5e636727a98aa33ce4e3a8dd7391d700d68a4208fc3b
ep_bytes: 558bec83c4ecff75e8515151684f5100
timestamp: 2005-06-14 17:08:58

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 3.80
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2008
OriginalFilename: WinRAR.exe
Comments: Translation © Dmitry Yerokhin 1999-2008

Graftor.296973 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.296973
FireEyeGeneric.mg.7af9d4e2c52149c4
ALYacGen:Variant.Graftor.296973
CylanceUnsafe
ZillyaWorm.Kolab.Win32.6669
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaExploit:Win32/ShellCode.d3375e4f
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.2c5214
BitDefenderThetaGen:NN.ZexaF.34212.Gm1@aS80c5ac
VirITTrojan.Win32.Agent2.CCRR
CyrenW32/S-301e7fab!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.KRS
TrendMicro-HouseCallTROJ_CRYPTR.SMKV
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.296973
NANO-AntivirusTrojan.Win32.Kolab.cznfx
SUPERAntiSpywareHeur.Agent/Gen-StaticIcon
APEXMalicious
TencentMalware.Win32.Gencirc.114c0d66
Ad-AwareGen:Variant.Graftor.296973
EmsisoftGen:Variant.Graftor.296973 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed.21467
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_CRYPTR.SMKV
McAfee-GW-EditionBehavesLike.Win32.Generic.hz
SophosMal/Generic-S
IkarusBackdoor.Win32.Rbot
GDataGen:Variant.Graftor.296973
JiangminWorm/Kolab.ivq
WebrootW32.Bot.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.180E028
ViRobotWorm.Win32.A.Net-Kolab.532208
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Slenfbot.gen!D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4017
Acronissuspicious
McAfeePWS-Spyeye.fe
VBA32Trojan.Zeus.EA.0999
RisingExploit.ShellCode!8.2A (CLOUD)
YandexWorm.Kolab!BXb67/HCATA
SentinelOneStatic AI – Malicious PE
FortinetW32/Slenfbot.AD!worm
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.296973?

Graftor.296973 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment