Malware

Should I remove “Graftor.494310 (B)”?

Malware Removal

The Graftor.494310 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.494310 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Graftor.494310 (B)?


File Info:

crc32: 94C27BB5
md5: 8f6403fd66032bb88c39be73dbce358d
name: 8F6403FD66032BB88C39BE73DBCE358D.mlw
sha1: 29c49e4c2684ab2d26a5985424f156668e857a85
sha256: 8bc6830254e1d1781470d3cdc060bc53a91c22cb4772e44d90e20bd31db74736
sha512: e46beab47ef47727b0c322f35699fd4377e6f9eb76c1e3a4c39bedaa95010e72b309d940446bd6a9835134bfbb12eb552141756f205b3f42ba4764b9a0305940
ssdeep: 3072:4JkQC2mCt3Q3BDieO4F5BfabJxzM9iGtTYqUiB1LPVxXPWfvCx:hRDH79Z4qUMLdw3e
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.494310 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005334f01 )
Elasticmalicious (high confidence)
ClamAVWin.Packer.Crypter-6539596-1
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Graftor.494310
MalwarebytesMalware.AI.1327112546
ZillyaTrojan.GenericKD.Win32.177533
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Graftor.494310
K7GWTrojan ( 005334f01 )
Cybereasonmalicious.d66032
BitDefenderThetaGen:NN.ZexaF.34670.kyW@aKqBWKhi
CyrenW32/S-eff9c904!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GHIQ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Mokes.fdsuie
MicroWorld-eScanGen:Variant.Graftor.494310
TencentWin32.Trojan.Generic.Ednw
Ad-AwareGen:Variant.Graftor.494310
SophosML/PE-A + Mal/GandCrab-D
ComodoTrojWare.Win32.PSW.Coins.GH@7ohrdk
DrWebTrojan.PWS.Stealer.23949
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.8f6403fd66032bb8
EmsisoftGen:Variant.Graftor.494310 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.eb
AviraHEUR/AGEN.1103318
eGambitUnsafe.AI_Score_87%
MicrosoftRansom:Win32/GandCrab.AG!bit
ArcabitTrojan.Graftor.D78AE6
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataWin32.Trojan.Kryptik.QP
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeeTrojan-FPSG!8F6403FD6603
MAXmalware (ai score=98)
VBA32BScope.TrojanRansom.GandCrypt
TrendMicro-HouseCallMal_HPGen-37b
RisingMalware.Undefined!8.C (CLOUD)
YandexTrojan.GenAsa!b58CJ2vz5a4
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.DWPH!tr
PandaTrj/Genetic.gen
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Graftor.494310 (B)?

Graftor.494310 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment