Malware

Graftor.647068 (B) removal tips

Malware Removal

The Graftor.647068 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.647068 (B) virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Panama)
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
addagapublicschool.com
helpdesk.keldon.info
coldheartedny.com
closerdaybyday.info
studiosundaytv.com
thejonesact.com

How to determine Graftor.647068 (B)?


File Info:

crc32: E74A40D6
md5: ad941d0ec221d7e68f626187452f9be6
name: AD941D0EC221D7E68F626187452F9BE6.mlw
sha1: 2398d35aea6effdbf7457586cf845d8dc32bad10
sha256: effc315b4d29b01820a3bae3014ae3d0b3738fd861507246571e6e101a4667ef
sha512: 2dc8a6e72d49256a3112e2a7d23387770be28d3621a675133d3ad27124ac84874714ea104b90d0cd6c319863d04e2e507977893c5091d8d78564d2286ea8982e
ssdeep: 3072:BZK+6eJ0vlXaauEV0alzolN2F8/qdiAZr2TgDGmzzc3aN1WsGX2ICn+FMf+hLJJ:BZK2wv0Kz62uuiVmHcKN1WsfznJ+h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: TODO:
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TODO:
Translation: 0x0421 0x04b0

Graftor.647068 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004e16e91 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4326
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt.C5
ALYacGen:Variant.Graftor.647068
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.11271
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004e16e91 )
Cybereasonmalicious.ec221d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.TeslaCrypt.L
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Razy-7101238-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.647068
NANO-AntivirusTrojan.Win32.Encoder.eerinu
MicroWorld-eScanGen:Variant.Graftor.647068
TencentWin32.Trojan.Filecoder.Lpuy
Ad-AwareGen:Variant.Graftor.647068
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.lu0@auW5sjHO
VIPRETrojan.Win32.Tescrypt.a (v)
McAfee-GW-EditionGenericRXFM-UB!AD941D0EC221
FireEyeGeneric.mg.ad941d0ec221d7e6
EmsisoftGen:Variant.Graftor.647068 (B)
JiangminTrojan.Generic.vrvl
AviraHEUR/AGEN.1108007
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1813653
MicrosoftRansom:Win32/Tescrypt.T
GDataGen:Variant.Graftor.647068
AhnLab-V3Trojan/Win32.Teslacrypt.R178173
Acronissuspicious
McAfeeGenericRXFM-UB!AD941D0EC221
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.664492479
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.98 (RDML:x3JkprIgofmqmH64dLlHPw)
YandexTrojan.Agent!GzUF24FptqI
IkarusTrojan-Ransom.TeslaCrypt
FortinetW32/Kryptik.4560!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.647068 (B)?

Graftor.647068 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment