Malware

Graftor.49539 removal instruction

Malware Removal

The Graftor.49539 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.49539 virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.49539?


File Info:

name: 29F91EA1B155D207EF98.mlw
path: /opt/CAPEv2/storage/binaries/a59e96084029e4f872ee2cfe5b012a25e40f5eb2cd8976260911d28c2a0960dd
crc32: 4BA0E72A
md5: 29f91ea1b155d207ef98e6b8c680359e
sha1: fb454f0cf4660118065c608bfb9a113ffbd4953f
sha256: a59e96084029e4f872ee2cfe5b012a25e40f5eb2cd8976260911d28c2a0960dd
sha512: aeda9e4f17b020017f53f26dbe6a96280bdcb3688c15fd713ff134caa86cfad07f3eb89110569e01eccddc0ce51ed342dd871092ecaaf09293203bb530ac8909
ssdeep: 1536:E49IoH+qGPLCEMWbImFe7fGfWXfpf3LmwmbvjUgfOGCj5kcOsUJlol:VH+TPLCEM7mIVPL2boSCj5kcOsU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108E36C317781C032C095103586A7C7B39A3DBD316BA4995BB788EB6E6F313D0EA36359
sha3_384: 5136c0ab3137a5969cefb203680e97b15c6a857678db0d27ecf7527d32ad8de9e8a0db03638782705db00cd63cf56f2c
ep_bytes: e8db640000e979feffff8bff558bec81
timestamp: 2012-10-31 14:58:54

Version Info:

CompanyName: Microsoft Corperation
FileDescription: Generic Host Process for Win32 Services
FileVersion: 1, 0, 1, 25
InternalName: Install.exe
LegalCopyright: Copyright (c) Microsoft. All rights reserved.
OriginalFilename: Install.exe
ProductName: Microsoft Windows Operating System
ProductVersion: 1, 0, 1, 25
Translation: 0x0412 0x04b0

Graftor.49539 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.49539
ClamAVWin.Trojan.Barys-9754805-0
FireEyeGeneric.mg.29f91ea1b155d207
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Graftor.49539
Cylanceunsafe
ZillyaTrojan.Generic.Win32.850101
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0048c2c71 )
K7AntiVirusTrojan ( 0048c2c71 )
BaiduWin32.Rootkit.Agent.s
CyrenW32/Urelas.DO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.R
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Graftor.49539
NANO-AntivirusTrojan.Win32.Swisyn.csiwzp
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Urelas.ha
TACHYONTrojan/W32.Swisyn.147456.Y
EmsisoftGen:Variant.Graftor.49539 (B)
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.DownLoader7.27838
VIPREGen:Variant.Graftor.49539
McAfee-GW-EditionBehavesLike.Win32.Trojan.cm
Trapminesuspicious.low.ml.score
SophosTroj/Urelas-AU
IkarusTrojan.Win32.Gupboot
GDataGen:Variant.Graftor.49539
JiangminTrojan.Generic.dlwxq
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.Swisyn
ArcabitTrojan.Graftor.DC183
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Urelas.AA
GoogleDetected
AhnLab-V3Trojan/Win32.PbBot.R42541
Acronissuspicious
McAfeeGeneric Malware.mt
MAXmalware (ai score=81)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Urelas!1.9D87 (CLASSIC)
YandexTrojan.Swisyn!NaOf4OcoGEI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.D!tr
BitDefenderThetaGen:NN.ZexaF.36196.jm0@aKOWcXeO
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.1b155d
DeepInstinctMALICIOUS

How to remove Graftor.49539?

Graftor.49539 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment