Malware

About “Graftor.496524” infection

Malware Removal

The Graftor.496524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.496524 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Graftor.496524?


File Info:

crc32: 15E9A675
md5: 171cb8f26dee6d5efd567b5f84be4831
name: 171CB8F26DEE6D5EFD567B5F84BE4831.mlw
sha1: 1d9b4dff84b2b07b8fab3a1c11bc4f6a22a63260
sha256: 24920135516b6976f4f3ebe79c2752494a1d324af2018a26045984d097653c93
sha512: 73aab28af2dd77dfe7a2d8350fd084b742b186e847ae322cb8273e7f85058d511c1284df801eb7e3152dc51c993d780ebe6e0a3ba8dcc16074ae22dffb51bf9c
ssdeep: 24576:9dyEWu2SSqWNdyQQQ8YPZ4Ik/MnVwILMaNiKFwNllC04Drkui1Z6H84GHvpYsa+9:9NR2SSqWeYPZbTftF8lh4DrkJhy+2yFR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) LegendSoft. 2006-2008
InternalName: LoginGate.exe
FileVersion: 1.0.0.0
CompanyName: LegendM2
LegalTrademarks: x767bx5f55x7f51x5173
Comments:
ProductName: x767bx5f55x7f51x5173
ProductVersion: 1.0.0.0
FileDescription: x767bx5f55x7f51x5173
OriginalFilename: LoginGate.exe
Translation: 0x0804 0x03a8

Graftor.496524 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.496524
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/NSAnti.3ce10811
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.26dee6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JAWTHKE
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.496524
NANO-AntivirusTrojan.Win32.Mlw.fedees
MicroWorld-eScanGen:Variant.Graftor.496524
TencentMalware.Win32.Gencirc.10b3487c
Ad-AwareGen:Variant.Graftor.496524
SophosMal/Generic-S
ComodoMalware@#qkju4wkdh7q2
BitDefenderThetaGen:NN.ZexaF.34266.rT1@a84uhhob
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Pate.tc
FireEyeGeneric.mg.171cb8f26dee6d5e
EmsisoftGen:Variant.Graftor.496524 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cfucp
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanSpy:Win32/Occamy.C
ArcabitTrojan.Graftor.D7938C
GDataGen:Variant.Graftor.496524
McAfeeGenericRXCC-UX!171CB8F26DEE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.UPX
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDML:TN13B9d00TI3UP6pWWPMZQ)
YandexTrojan.Agent!MSnIR9+VSWk
IkarusVirus.Win32.NSAnti
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.UX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.496524?

Graftor.496524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment