Malware

Graftor.360703 information

Malware Removal

The Graftor.360703 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.360703 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.360703?


File Info:

crc32: 1D19FCDE
md5: 309cf0161d1170c63657277c1ea038f5
name: 309CF0161D1170C63657277C1EA038F5.mlw
sha1: e13ace1d80c10221a35017e76d9f23642b65f4fe
sha256: ea5a47ff2ae0b0922b70f25944b690e95267fc83043279be2ea895b5cab5410d
sha512: 27d12d63d1d99c9631084b2aa09c993ce05b77e14bea145e6672953052190e73058f215aee0ccf1bded8e2050c833082d84a8e5c164be5c7651802509f95960c
ssdeep: 3072:oCGhNy3TVOtAQTVUraBH5AVibBFYKe6EOSO8qlQTbXOqFNLy8sZL0iL3:oCGjy3GFVUrb+BFYTOSO8iwbxfLydT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: SAGA Incorporated, Copyright (C) 1998
InternalName: DSplit
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Dynamic splitter (demo)
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Dynamic splitter (demo)
OriginalFilename: DSplit.EXE
Translation: 0x0409 0x04b0

Graftor.360703 also known as:

K7AntiVirusTrojan ( 005085a41 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.9309
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5248420
ALYacTrojan.Ransom.Sage
CylanceUnsafe
ZillyaTrojan.SageCrypt.Win32.365
SangforTrojan.Win32.Injector.DMGM
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/SageCrypt.1d48bb8d
K7GWTrojan ( 005085a41 )
Cybereasonmalicious.61d117
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DMGM
ZonerTrojan.Win32.54882
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Yakes-6991209-0
KasperskyTrojan-Ransom.Win32.SageCrypt.ahg
BitDefenderGen:Variant.Graftor.360703
NANO-AntivirusTrojan.Win32.Shade.emfvzo
MicroWorld-eScanGen:Variant.Graftor.360703
TencentMalware.Win32.Gencirc.10b587b7
Ad-AwareGen:Variant.Graftor.360703
SophosML/PE-A
ComodoMalware@#3q0vt92aafs4y
BitDefenderThetaGen:NN.ZexaF.34236.lqX@ayrn6Jpj
VIPRETrojan.Win32.Injector.cdgy (v)
TrendMicroRansom_SageCrypt.R002C0OK121
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.309cf0161d1170c6
EmsisoftGen:Variant.Graftor.360703 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.SageCrypt.v
AviraHEUR/AGEN.1112553
Antiy-AVLTrojan/Generic.ASMalwS.1EE1098
MicrosoftRansom:Win32/Milicry.A
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.ahg
GDataGen:Variant.Graftor.360703
AhnLab-V3Trojan/Win32.SageCrypt.R196493
Acronissuspicious
McAfeeTrojan-FLPF!309CF0161D11
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:gnVtHDvFUomz3MTGLpkmdQ)
YandexTrojan.GenAsa!l00Yha/eflo
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DMKX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.360703?

Graftor.360703 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment