Malware

What is “Graftor.614592”?

Malware Removal

The Graftor.614592 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.614592 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.614592?


File Info:

crc32: E073F196
md5: 44c51734631ad98c8d740aeb47fc51b7
name: 44C51734631AD98C8D740AEB47FC51B7.mlw
sha1: 24cb7cfa19297e2138bea56a330abab7bc0f51dc
sha256: 699beab2a7ffa4dea85ea703f6001b4b04652d128f1e520399860f5b7cccfcb7
sha512: 755a6683c55fd3c28c5cbce2ae17df538860bbe712ef87829426885d26140e44e642a52623bcebdda87dcd68542d83de1f6e6f2f420f5d9b76ba38944ad06a29
ssdeep: 1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIZv:ymb3NkkiQ3mdBjFIZv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.614592 also known as:

BkavHW32.Packed.
DrWebTrojan.Inject1.58305
MicroWorld-eScanGen:Variant.Graftor.614592
ALYacGen:Variant.Graftor.614592
CylanceUnsafe
ZillyaTrojan.Generic.Win32.643973
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Ganelp.bc5a1be0
K7GWTrojan ( 005003ac1 )
K7AntiVirusTrojan ( 005003ac1 )
TrendMicroTROJ_GEN.R002C0DE620
CyrenW32/BlackMoon.P.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.614592
KasperskyHEUR:Backdoor.Win32.Tiny.gen
BitDefenderGen:Variant.Graftor.614592
ViRobotTrojan.Win32.Z.Graftor.56216
TencentMalware.Win32.Gencirc.10b55473
Ad-AwareGen:Variant.Graftor.614592
SophosTroj/Agent-BBMW
ComodoBackdoor.Win32.Agent.BVX@8hj67l
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34110.diX@ai09iRm
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.44c51734631ad98c
EmsisoftGen:Variant.Graftor.614592 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/BlackMoon.P.gen!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_88%
Antiy-AVLGrayWare/Win32.BlackMoon.a
MicrosoftWorm:Win32/Ganelp
ArcabitTrojan.Graftor.D960C0
AegisLabTrojan.Win32.Tiny.m!e
ZoneAlarmHEUR:Trojan.Win32.Generic
TACHYONTrojan/W32.Blamon
AhnLab-V3Malware/RL.Generic.R256000
Acronissuspicious
McAfeeGenericRXKA-HL!44C51734631A
MAXmalware (ai score=83)
VBA32TrojanDropper.Dinwod
MalwarebytesTrojan.Vundo
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DE620
RisingTrojan.Agent!1.B82B (CLOUD)
YandexTrojan.Agent!HE+5Phr7t7I
IkarusTrojan.Vundo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Pliskal.B!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Wacatac.A

How to remove Graftor.614592?

Graftor.614592 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment