Malware

Graftor.442387 information

Malware Removal

The Graftor.442387 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.442387 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Graftor.442387?


File Info:

crc32: 220FA4FA
md5: a1ba0bc184d774e3a4f6b1553c353c08
name: A1BA0BC184D774E3A4F6B1553C353C08.mlw
sha1: 076ca91f2e1d7effcb3254fa6f70d0a54d879b13
sha256: f8edd03f9ccab2bd6f9ae5bb3e6f662b04642c421a91242bba2c8c98ec79f2a1
sha512: e5c0080da360fac17a8b588813a8d590dfc3b05df30f7b410781873057b91c477e411726a20f22fe7b042f5954474644cdc87061638a887b276282c969af4bd1
ssdeep: 3072:mVfkV1cUmhK0Xur8rSsIt2G8OcGQ6dcR4Oyynjg8Bvp4JG8Rl7xTOY3sX:CkVhG5nuMJ6dc+N8tp45Rl7xTO3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: AVAST Software Copyright xa9. All rights reserved.
CompanyName: AVAST Software
Comments: Specified Rez Foxpro Animals Sclk
ProductName: Unconceal
ProductVersion: 1.6.4.5
FileDescription: Specified Rez Foxpro Animals Sclk
Translation: 0x0409 0x04b0

Graftor.442387 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Graftor.442387
FireEyeGeneric.mg.a1ba0bc184d774e3
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056e92e1 )
BitDefenderGen:Variant.Graftor.442387
K7GWTrojan ( 0056e92e1 )
Cybereasonmalicious.184d77
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Androm.oouf
NANO-AntivirusTrojan.Win32.Androm.evfsmi
AegisLabTrojan.Win32.Androm.4!c
RisingTrojan.Generic@ML.94 (RDML:DMy5ffm1QKFZLk2QhRzBSQ)
Ad-AwareGen:Variant.Graftor.442387
EmsisoftGen:Variant.Graftor.442387 (B)
ComodoMalware@#pmhy1neypg7k
F-SecureHeuristic.HEUR/AGEN.1128656
SophosMal/Generic-S + Mal/Kryptik-DC
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1128656
MAXmalware (ai score=87)
MicrosoftTrojanDownloader:Win32/Dofoil.AC
ArcabitTrojan.Graftor.D6C013
ZoneAlarmBackdoor.Win32.Androm.oouf
GDataGen:Variant.Graftor.442387
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Locky.R192960
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.kq0@a8c@g0fi
TACHYONRansom/W32.Locky.179712.E
VBA32BScope.TrojanSpy.Panda
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FQPO
TencentWin32.Backdoor.Androm.Lmas
YandexBackdoor.Androm!cfTxK+pZ4zU
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/Androm.OOUF!tr.bdr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.442387?

Graftor.442387 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment