Malware

Graftor.470764 removal instruction

Malware Removal

The Graftor.470764 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.470764 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.470764?


File Info:

crc32: C66A60D3
md5: 08ac3a018fc5eee32d828ef96173ed05
name: 08AC3A018FC5EEE32D828EF96173ED05.mlw
sha1: 10507145b73f8256f44e8bfc75be7ecaa4ec32f1
sha256: f8cacbce640654e4d3192139a971fbd0998e8396191399c8fac5794b8bad9b87
sha512: e81e17e941a8607690f6e2092f6271c89755e01f8b0d9de6c928b6112cd1a7935440f036646b925e6a27d4960ae0ef3d20306849c33f72bd6d18d233b554d100
ssdeep: 12288:/KALl7bdH/cFktbmANDr+DgC127aykTR2II9oS:/7hN0FeblN+Z12eykTHI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x65b0x4e00 x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x65b0x4e00
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: Bx52a9x624b-x54d4x54e9x54d4x54e9x8d26x53f7x7ba1x7406
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Graftor.470764 also known as:

K7AntiVirusTrojan ( 005246d51 )
MicroWorld-eScanGen:Variant.Graftor.470764
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Graftor.470764
CylanceUnsafe
CrowdStrikemalicious_confidence_100% (D)
K7GWTrojan ( 00013a151 )
CyrenW32/GenPua.08AC3A01!Olympus
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
GDataWin32.Application.PUPStudio.A
BitDefenderGen:Variant.Graftor.470764
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
Ad-AwareGen:Variant.Graftor.470764
SophosGeneric PUA BA (PUA)
F-SecureGen:Variant.Graftor.470764
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.gc
EmsisoftGen:Variant.Graftor.470764 (B)
SentinelOnestatic engine – malicious
Endgamemalicious (moderate confidence)
WebrootW32.Malware.gen
MicrosoftPUA:Win32/Presenoker
ArcabitTrojan.Graftor.D72EEC
McAfeeArtemis!08AC3A018FC5
MAXmalware (ai score=96)
Paloaltogeneric.ml

How to remove Graftor.470764?

Graftor.470764 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment