Malware

Graftor.573749 (B) removal tips

Malware Removal

The Graftor.573749 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.573749 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.573749 (B)?


File Info:

name: 31B014026A755ED6D56F.mlw
path: /opt/CAPEv2/storage/binaries/1bf10c2da2e155381bf852e418231829cd4767ed385aab0f3012c58988a3bf10
crc32: 32CBC964
md5: 31b014026a755ed6d56f3dd8e132d8de
sha1: 6fca25153f83e132c1b1948870ba87c6f7a65bf1
sha256: 1bf10c2da2e155381bf852e418231829cd4767ed385aab0f3012c58988a3bf10
sha512: 9124c9007234a15fafa3320348148600c7b55ac25d14f98cf6dc2273c7c2c104e0d8b7cfeb01e4c5497de6b777f8934834b0e9d9367eca8bc496cfaf17cfa8c3
ssdeep: 6144:yvK7x5ewPBoOpwJRxf6BoSg/TbkNMvStTov6rthzqZS8Bhohf4PdIbAw0/bKW:yS7ZPFuRx8avkPtT5mZS8YF4FI0buW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F584BF2026E5827ED27B1034DBF856F0B499E35C8F2499C7A3C48AAD0E76F87D53462D
sha3_384: 151112fcdba3b39b94d0af3cec892b9652047d51d1f1503aac9ed51223d20f8c290a21744de6854c8ffa2b16b704af2f
ep_bytes: 558bec6aff68509b420068544f420064
timestamp: 2018-01-28 15:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 18.01
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 18.01
Translation: 0x0409 0x04b0

Graftor.573749 (B) also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.573749
FireEyeGeneric.mg.31b014026a755ed6
ALYacGen:Variant.Graftor.573749
CylanceUnsafe
SangforTrojan.Win32.Updane.gen
K7AntiVirusTrojan ( 0053d67e1 )
AlibabaTrojan:Win32/Updane.9fa322e1
K7GWTrojan ( 0053d67e1 )
Cybereasonmalicious.26a755
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Updane.G.gen
TrendMicro-HouseCallTROJ_GEN.R002C0GKA21
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Updane.gen
BitDefenderGen:Variant.Graftor.573749
Ad-AwareGen:Variant.Graftor.573749
ComodoMalware@#blgcu32whylg
TrendMicroTROJ_GEN.R002C0GKA21
EmsisoftGen:Variant.Graftor.573749 (B)
GDataGen:Variant.Graftor.573749
AviraTR/Patched.DealPly.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.2C66EDB
MicrosoftTrojan:Win32/Occamy.C1B
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C2833490
McAfeeRDN/Generic.grp
MAXmalware (ai score=85)
VBA32Trojan.Updane
MalwarebytesMalware.AI.2262964711
APEXMalicious
MaxSecureTrojan.Malware.74549449.susgen
FortinetW32/Updane.A!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Graftor.573749 (B)?

Graftor.573749 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment