Malware

Graftor.494450 removal guide

Malware Removal

The Graftor.494450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.494450 virus can do?

  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

www.baidu.com
www.by8.tech
ocsp.digicert.com
cdn.bootcss.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Graftor.494450?


File Info:

crc32: 0F1C585D
md5: 37695d5c16a3006116e6fce9977a4d02
name: bytkzs.exe
sha1: 49069eb0924ae07043079afbea528338f8e7b7df
sha256: ce4ed98aeee9e29a3dc41232180a276d08752cc6c34ec08fb078183b26e08217
sha512: e8acb21aaedb19e593ff4dd1558a5e3817c9fb21c070e3368b4406aa23f0ecf179610f7f50e54df4c6051e9b8a257bd4d87a0d9b8e95c5c467644f36d247550e
ssdeep: 24576:1kCqjND8Clx0YS89T/0GnT3ckG6exTxeQUeu1dDYHjLxQ7:1KjNH0YSAG7Kx8HQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.494450 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Graftor.494450
FireEyeGeneric.mg.37695d5c16a30061
McAfeeArtemis!37695D5C16A3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.494450
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZexaF.34132.vrZ@aqFrdlnb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Zusy-6840460-0
GDataGen:Variant.Graftor.494450
AlibabaTrojanDropper:Win32/FlyStudio.362dca11
TencentWin32.Trojan.Graftor.Ljuf
Ad-AwareGen:Variant.Graftor.494450
SophosGeneric PUA MD (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
EmsisoftGen:Variant.Graftor.494450 (B)
F-ProtW32/Trojan.CLL.gen!Eldorado
JiangminBackdoor.Poison.bps
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.D78B72
MicrosoftTrojan:Win32/Ymacco.AACE
CynetMalicious (score: 100)
VBA32BScope.Trojan.Bitrep
ALYacGen:Variant.Graftor.494450
MAXmalware (ai score=88)
ESET-NOD32a variant of Win32/TrojanDropper.FlyStudio.CH
TrendMicro-HouseCallTROJ_GEN.R015H0CG320
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/QQWare.A!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.c16a30
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM41.2.593B.Malware.Gen

How to remove Graftor.494450?

Graftor.494450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment