Malware

Graftor.6749 (file analysis)

Malware Removal

The Graftor.6749 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.6749 virus can do?

  • Executable code extraction
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.6749?


File Info:

crc32: E2138422
md5: 9952e5681f60deb0f279468ca53aef36
name: 9952E5681F60DEB0F279468CA53AEF36.mlw
sha1: 2e414662099fd36cf00a98e86340f47a0edf7b19
sha256: 23731969e7c2ffaca75be29f347c735a7f55d19532509c7d99d61285f884ff2d
sha512: a25de2321975202347c10eed07f119e84df0781fb35283a61abdeef18f3c7e1a099a681c91df00bb5f5cd830f17b94773664d1f7687b54c82ef3ec19a5dc53ca
ssdeep: 6144:4xxipI22oFqph+zb4IGDm4Jk75UIWjn3IZQ80w+By6u5Y2/RF2jQKwRhzdaZAXO:WouCim4ELm2lbevj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: ohwajzuvrhkt
InternalName: xolpbesgxrot
FileVersion: 22.25.0009
CompanyName: HZDSOLRK
LegalTrademarks: gkimxuykepd
Comments: ECYLHRCQKZ
ProductName: OATNRWUXDJQPOAWPIBHZDSO
ProductVersion: 22.25.0009
FileDescription: FFGSVMXLJYVTUZXM
OriginalFilename: xolpbesgxrot.exe

Graftor.6749 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.24651
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.6749
CylanceUnsafe
ZillyaTrojan.Delf.Win32.76654
SangforPUP.Win32.Graftor.6749
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDownloader:Win32/VBKrypt.9a39773b
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.81f60d
CyrenW32/VBInject.1!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.OBD
APEXMalicious
AvastWin32:Inject-AFS [Trj]
KasperskyTrojan.Win32.VBKrypt.cugq
BitDefenderGen:Variant.Graftor.6749
NANO-AntivirusTrojan.Win32.VBKrypt.fcscus
MicroWorld-eScanGen:Variant.Graftor.6749
TencentWin32.Trojan.Vbkrypt.Htvm
Ad-AwareGen:Variant.Graftor.6749
SophosML/PE-A + Mal/VBCheMan-A
ComodoSuspicious@#1hr4gaf45ixxk
BitDefenderThetaAI:Packer.41E62EFE21
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
FireEyeGeneric.mg.9952e5681f60deb0
EmsisoftGen:Variant.Graftor.6749 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraWORM/Streab.E.1
Antiy-AVLTrojan/Generic.ASMalwS.199F67B
MicrosoftTrojanDownloader:Win32/Umbald.A
GDataGen:Variant.Graftor.6749
McAfeeArtemis!9952E5681F60
MAXmalware (ai score=100)
VBA32BScope.Trojan.VBKrypt
MalwarebytesMalware.AI.1399509005
PandaTrj/CI.A
YandexTrojan.VBKrypt!HqmPw83LOkU
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.CZLQ!tr
AVGWin32:Inject-AFS [Trj]
Paloaltogeneric.ml

How to remove Graftor.6749?

Graftor.6749 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment