Malware

About “Graftor.372504” infection

Malware Removal

The Graftor.372504 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.372504 virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
sd9.ren

How to determine Graftor.372504?


File Info:

crc32: D9E9267D
md5: d7cfcffec1fd595fcb0db216cefb4af4
name: D7CFCFFEC1FD595FCB0DB216CEFB4AF4.mlw
sha1: 14377338bd81a3c4f44f36563b0ea05295aeeb9b
sha256: 02f3e0d3713dc386d7965403ab1fcb8d225f9e81900ffc7e688300d9b7c8442a
sha512: 8ba9552a256e7f980e93a973a12fff3be7a48a3dab31480b68722b62677d62f590d942227eafc65ff22e0eab7c06e1112e7b1c3450aab84d4d72ada56164d975
ssdeep: 1536:4PIHf7coWWV7BckjThNltK0htrgh3izODDQ0QoNci5rjLK0BAczerM0nl5x:4PI/0YBpjVd1eiSo5o2i5O0BBz8jl5x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2001
InternalName: Slide
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Slide x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Slide Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Slide.EXE
Translation: 0x0804 0x04b0

Graftor.372504 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00521b151 )
LionicTrojan.Win32.Zegost.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.10190
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Graftor.372504
CylanceUnsafe
ZillyaBackdoor.Zegost.Win32.5532
SangforBackdoor.Win32.Zegost.mtggk
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Zegost.8df2bee4
K7GWTrojan ( 00521b151 )
Cybereasonmalicious.ec1fd5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.BLHD
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Zegost.mtggk
BitDefenderGen:Variant.Graftor.372504
NANO-AntivirusTrojan.Win32.Zegost.exeihf
MicroWorld-eScanGen:Variant.Graftor.372504
TencentWin32.Backdoor.Zegost.Wtnr
Ad-AwareGen:Variant.Graftor.372504
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanProxy.Horst.~O@f80r9
BitDefenderThetaGen:NN.ZexaF.34294.hq0@ae70QRBT
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionGenericRXDV-LC!D7CFCFFEC1FD
FireEyeGeneric.mg.d7cfcffec1fd595f
EmsisoftGen:Variant.Graftor.372504 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Zegost.uv
AviraHEUR/AGEN.1111320
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.23F2F1E
MicrosoftTrojan:Win32/TrickBot.RT!MTB
GDataGen:Variant.Graftor.372504
AhnLab-V3Backdoor/Win32.Zegost.C2347347
Acronissuspicious
McAfeeGenericRXDV-LC!D7CFCFFEC1FD
MAXmalware (ai score=98)
VBA32Backdoor.Zegost
PandaTrj/GdSda.A
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingTrojan.Generic@ML.100 (RDML:OmbhMKgREoq+XLKi5/aTeg)
YandexTrojan.GenAsa!RVRyPSQbm3k
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.EGBG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.372504?

Graftor.372504 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment