Malware

Graftor.302555 (file analysis)

Malware Removal

The Graftor.302555 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.302555 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.302555?


File Info:

crc32: FC434FD4
md5: 8552647a980f286423f840530eac7440
name: 8552647A980F286423F840530EAC7440.mlw
sha1: 4c766dba686f41e21b154bef5a9574f914c0cf11
sha256: 1a1188be5fe025c4fdabf2e7db47ce56d0c38570af2d0b09681975b913f8f9be
sha512: 86a9b0773dddca2c13b9cc22736e7adc08d311b46b9999739bb94c1f24025df6db1dcb2de2f256650d072b2ba8a8cb6ff2c5d8e709e88900c4e6da1ec5aed02b
ssdeep: 49152:gVUxN4R6XzDOnEZsdYN/2qeHpomFsEhXLeSBST1WWS:EUxHjDOEfN/2qe3FscOWx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.302555 also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.27237
CynetMalicious (score: 100)
CAT-QuickHealPUA.DiplugemPMF.S18031841
ALYacGen:Variant.Graftor.302555
CylanceUnsafe
ZillyaTool.Gamehack.Win32.5
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a980f2
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHackTool.Win32.Gamehack.aiju
BitDefenderGen:Variant.Graftor.302555
NANO-AntivirusTrojan.Win32.Drop.eaezaj
MicroWorld-eScanGen:Variant.Graftor.302555
TencentMalware.Win32.Gencirc.10b0da06
Ad-AwareGen:Variant.Graftor.302555
SophosTroj/Agent-BDUR
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34236.TsY@aixT!ifb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.8552647a980f2864
EmsisoftAdware.Generic (A)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.Gamehack.bey
WebrootW32.Trojan.Gen
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftBrowserModifier:Win32/Diplugem
ArcabitTrojan.Graftor.D49DDB
ZoneAlarmHackTool.Win32.Gamehack.aiju
GDataWin32.Trojan.PSE.12FI8JT
AhnLab-V3Malware/Gen.Generic.C1346377
Acronissuspicious
McAfeeGenericRXAA-OF!8552647A980F
MAXmalware (ai score=99)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.FlyStudio
PandaTrj/Genetic.gen
RisingTrojan.Spawnerx!1.C489 (CLASSIC)
YandexRiskware.Gamehack!15fQchEZRl4
IkarusBHO.Win32.Diplugem
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.302555?

Graftor.302555 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment