Malware

Graftor.448469 (file analysis)

Malware Removal

The Graftor.448469 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.448469 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.adobe.com
simpledomain.biz

How to determine Graftor.448469?


File Info:

crc32: ACF97E5F
md5: acd4ccb71b5df020ea7f6a38e6b11100
name: ACD4CCB71B5DF020EA7F6A38E6B11100.mlw
sha1: acbd1cac917606dea673c209a87048573fc1ec7f
sha256: f8f4c626eeec9e4e304cfa67484b767d30d665c432116ba20a7a888852e6d1f2
sha512: 1095b0b1d9a32ab5e97f44ac1ce37f85d9a2cf6305f2a2678de9e8e51be98c3a5421e04640ad262e9c10bc7ca2f4c71aa2fd58583198bcb338b9532b3ffe074a
ssdeep: 1536:np1FJhMhXuycAxt5j1BSavYowmOFTMfgwsTNDoqYaAeqaiUDef:zhMhXB7rvzwbFI+NsqYaAebiUDef
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa92005-2015 IObit
InternalName:
FileVersion: 8.2.3.3364
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: Initialization Program
ProductVersion: 8.0.0.0
FileDescription: Advanced SystemCare 8 Initialization
OriginalFilename:
Translation: 0x0409 0x04e4

Graftor.448469 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.448469
FireEyeGeneric.mg.acd4ccb71b5df020
Qihoo-360Win32/Backdoor.39d
ALYacGen:Variant.Graftor.448469
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005224381 )
BitDefenderGen:Variant.Graftor.448469
K7GWTrojan ( 005224381 )
Cybereasonmalicious.71b5df
BitDefenderThetaGen:NN.ZexaF.34804.gq0@amJyG6jb
CyrenW32/S-68b4cf76!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FHBM
BaiduWin32.Trojan.Kryptik.alb
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Androm.oqqb
AlibabaBackdoor:Win32/Androm.612a51e4
NANO-AntivirusTrojan.Win32.Androm.evpack
Ad-AwareGen:Variant.Graftor.448469
EmsisoftGen:Variant.Graftor.448469 (B)
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.DownLoader25.64286
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroMal_Cerber-11
McAfee-GW-EditionGenericRXLD-FR!ACD4CCB71B5D
SophosML/PE-A + Mal/Cerber-K
IkarusTrojan.Win32.Crypt
JiangminBackdoor.Androm.aoxq
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojanDownloader:Win32/Dofoil.AC
ArcabitTrojan.Graftor.D6D7D5
ZoneAlarmBackdoor.Win32.Androm.oqqb
GDataGen:Variant.Graftor.448469
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXLD-FR!ACD4CCB71B5D
MAXmalware (ai score=99)
VBA32BScope.Backdoor.Vawtrak
MalwarebytesRansom.Cerber
PandaTrj/Hexas.HEU
TrendMicro-HouseCallMal_Cerber-11
RisingTrojan.Kryptik!1.AE9C (CLASSIC)
YandexBackdoor.Androm!i7rFKjCPc28
SentinelOneStatic AI – Malicious PE – Ransomware
eGambitUnsafe.AI_Score_99%
FortinetW32/Dridex.IZC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.448469?

Graftor.448469 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment