Malware

Should I remove “Graftor.555449”?

Malware Removal

The Graftor.555449 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.555449 virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.555449?


File Info:

crc32: BC24AB93
md5: 06d3b692d7abe60f4ac06342b3283a85
name: 06D3B692D7ABE60F4AC06342B3283A85.mlw
sha1: 28635a98f6a5d0e35f97b18e334ec2d06099da62
sha256: 1a368f726578a251ad865b24e1e8a166d4fc5937373dd71b9c1662725fce3aed
sha512: 2474df88e3b70a407fdabdd60a2713b152b42e7be668b09083fabd2853df98b9601d74e661bb166a871492a5a612dade12a3928ac1ec93d946d165bf528e836f
ssdeep: 12288:RgnJrAxqupV6PGgErQ3KwUcgxOxqHpYDMJapcdFpO08bhZ:GnJSqupViGgBNUTOxmLXPpO08dZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.555449 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Siggen7.22063
CynetMalicious (score: 99)
CAT-QuickHealBackdoor.MsilIH.S12061634
ALYacGen:Variant.Graftor.555449
CylanceUnsafe
ZillyaBackdoor.SpyGate.Win32.1035
AlibabaBackdoor:MSIL/SpyGate.c4e3da2c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2d7abe
CyrenW32/Ulise.CU.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of Generik.EXNZVQL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Jacard-7423990-0
KasperskyBackdoor.MSIL.SpyGate.plg
BitDefenderGen:Variant.Graftor.555449
NANO-AntivirusTrojan.Win32.Bladabindi.emgbby
MicroWorld-eScanGen:Variant.Graftor.555449
TencentMsil.Backdoor.Spygate.Hff
SophosGeneric Reputation PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Worm.hc
FireEyeGeneric.mg.06d3b692d7abe60f
EmsisoftGen:Variant.Graftor.555449 (B)
JiangminBackdoor.MSIL.lgk
AviraBDS/SpyGate.denpe
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftMalware.Win32.Gen.cc!s1
AegisLabTrojan.MSIL.SpyGate.m!c
GDataGen:Variant.Graftor.555449 (2x)
McAfeeArtemis!06D3B692D7AB
MAXmalware (ai score=81)
VBA32Backdoor.MSIL.SpyGate
MalwarebytesMalware.AI.1253657794
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CE321
RisingBackdoor.SpyGate!8.E154 (CLOUD)
YandexTrojan.GenAsa!eH8+VWpU9Fg
IkarusTrojan.Atros5
FortinetW32/SpyGate.PLG!tr.bdr
AVGWin32:Malware-gen

How to remove Graftor.555449?

Graftor.555449 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment