Malware

Graftor.531304 (file analysis)

Malware Removal

The Graftor.531304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.531304 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.531304?


File Info:

crc32: 0DEFF441
md5: 2ecf6793d8822f60a050065226adde19
name: 2ECF6793D8822F60A050065226ADDE19.mlw
sha1: 746ece62f2f4788ba7397525b8cd50b4a431d82f
sha256: 8f88671653b2d94afae8b6420e654171aad727b9b9091c0b510cd90e0765ed8f
sha512: e005d26429d9d1bb0b718dd2791fbe289d9504a5f4da9fde5d43b6245089ee39955442127a62e5fbd3178a1545af00651f15fc44fb31591efc3a8ef7c28107da
ssdeep: 3072:mpq6ldtieqJUgrQD92iaFEWdsviSWl5I33mAcjcLgMc4mzrzI/Xh9+pjXjBlmC+:dsricgrQDl2EusvioNOSXz+pDje/U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: CTestProgressBar
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CTestProgressBar Application
ProductVersion: 1, 0, 0, 1
FileDescription: CTestProgressBar MFC Application
OriginalFilename: CTestProgressBar.EXE
Translation: 0x0409 0x04b0

Graftor.531304 also known as:

K7AntiVirusTrojan ( 0052dbfd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.10690
CynetMalicious (score: 90)
ALYacGen:Variant.Graftor.531304
CylanceUnsafe
ZillyaBackdoor.Farfli.Win32.7959
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0052dbfd1 )
Cybereasonmalicious.3d8822
CyrenW32/Injector.ABK.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EEOZ
ZonerTrojan.Win32.72923
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
BitDefenderGen:Variant.Graftor.531304
NANO-AntivirusTrojan.Win32.Farfli.fjfynq
MicroWorld-eScanGen:Variant.Graftor.531304
TencentMalware.Win32.Gencirc.113ab1d6
Ad-AwareGen:Variant.Graftor.531304
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1136922
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionGenericR-OOF!2ECF6793D882
FireEyeGeneric.mg.2ecf6793d8822f60
EmsisoftGen:Variant.Graftor.531304 (B)
JiangminBackdoor.Farfli.cph
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1136922
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
MicrosoftTrojan:Win32/Farfli.DSK!MTB
ArcabitTrojan.Graftor.D81B68
GDataGen:Variant.Graftor.531304
McAfeeGenericR-OOF!2ECF6793D882
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Farfli
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
RisingBackdoor.Farfli!8.B4 (TFE:5:6rF65RmTftS)
YandexTrojan.GenAsa!aaMXUxidX1U
IkarusTrojan.Win32.Injector
FortinetW32/Injector.EEOZ!tr
AVGWin32:BackdoorX-gen [Trj]

How to remove Graftor.531304?

Graftor.531304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment