Malware

How to remove “Graftor.597040”?

Malware Removal

The Graftor.597040 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.597040 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Graftor.597040?


File Info:

crc32: F281F4A6
md5: 4a59c8f4bdf31e8e73c6bbe1daf5e677
name: 4A59C8F4BDF31E8E73C6BBE1DAF5E677.mlw
sha1: c6d65135bac0cab8fc4ec87217315ed1bb41fe7e
sha256: 5a83f25dc02fd75c8e2203f8b967574178df0bb2d9809e5de7069cbfe8c34f13
sha512: 087719e6d1d0d4105628238bddfea2bbd7a27447a27b55ee2f542d45df99973fde4b26478428913873cb1c79aad34e850bda6361dc0ad5e2e68011a71cf9e08c
ssdeep: 3072:K1eSFG0tXAR+JMCX3LuI7Jdw603GwCGEqqSjl0:e44AYLnLNxiGjqHl0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Windows Core Module
FileVersion: 6.3.9600.16384
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.3.9600.16384
FileDescription: Windows Core Module
OriginalFilename: Windows Core Module
Translation: 0x0409 0x04b0

Graftor.597040 also known as:

BkavW32.SmbhostPOI.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Vools.17
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentPMF.S5648627
ALYacGen:Variant.Graftor.597040
CylanceUnsafe
ZillyaTrojan.Vools.Win32.15
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0054a37e1 )
K7AntiVirusTrojan ( 0054a37e1 )
CyrenW32/Trojan.AVUZ-9302
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Vools.L
ZonerTrojan.Win32.77799
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Coinminer-7000567-1
KasperskyTrojan.Win32.Agentb.jlys
BitDefenderGen:Variant.Graftor.597040
NANO-AntivirusTrojan.Win32.Vools.huxevx
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanGen:Variant.Graftor.597040
TencentTrojan.Win32.Vools.c
Ad-AwareGen:Variant.Graftor.597040
SophosML/PE-A + Troj/Vools-R
ComodoTrojWare.Win32.Vools.AC@845n1f
BitDefenderThetaGen:NN.ZedlaF.34688.gu8@aSp8W@ci
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.VOOLS.SMAL01
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
FireEyeGeneric.mg.4a59c8f4bdf31e8e
EmsisoftGen:Variant.Graftor.597040 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agentb.fdx
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1107841
MicrosoftTrojan:Win32/Attolv
GridinsoftTrojan.Win32.Agent.vb!s1
GDataGen:Variant.Graftor.597040
TACHYONTrojan/W32.Agent.109056.ZA
AhnLab-V3Malware/Win32.Generic.C3115435
McAfeeTrojan-FQVA!4A59C8F4BDF3
MAXmalware (ai score=82)
VBA32Trojan.Agentb
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.VOOLS.SMAL01
RisingWorm.Win32.EternalBlueMiner.u!0.18F169 (KTSE)
YandexTrojan.GenAsa!fENHHmENLdA
IkarusTrojan.Win32.Vools
FortinetW32/Vools.L!tr
AVGWin32:Malware-gen

How to remove Graftor.597040?

Graftor.597040 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment