Malware

Graftor.681857 removal instruction

Malware Removal

The Graftor.681857 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.681857 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
ipv4bot.whatismyipaddress.com
a.tomx.xyz

How to determine Graftor.681857?


File Info:

crc32: 00FB84BE
md5: 346ec17a6d9f3ed4631bef35acf8d31b
name: 346EC17A6D9F3ED4631BEF35ACF8D31B.mlw
sha1: 87100c2a89a6e6dd0a3dcbe0e4d31b9b03eb4f81
sha256: 3fc7a21bb3d4fad571b92e7645cd051a28fe5a9533a536090fe4ffc2e96555b5
sha512: 17050699246a418763a6502c5b0b790e0688a05fbcd6f07afed913772d83ec5ee715998deb0db056d2737999f896e40045bd9d03e3b6273c65237d6ad2667300
ssdeep: 6144:LUfUgkfpsSqNnh2U+Hv56xdvXPM8tHgtcvsigniJJy1:LUfULR5Hv0fXPMIgt4Ja
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.681857 also known as:

K7AntiVirusTrojan ( 0055b9671 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.38757
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
AlibabaTrojan:Win32/DelShad.35b0ae22
K7GWTrojan ( 0055b9671 )
Cybereasonmalicious.a6d9f3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.GandCrab.G
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.DelShad.bpg
BitDefenderGen:Variant.Graftor.681857
NANO-AntivirusTrojan.Win32.Filecoder.gibtxj
ViRobotTrojan.Win32.S.Ransom.350064
MicroWorld-eScanGen:Variant.Graftor.681857
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Graftor.681857
SophosMal/Generic-S
TrendMicroRansom_Cryptolocker.R007C0DGP21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.346ec17a6d9f3ed4
EmsisoftGen:Variant.Graftor.681857 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.RansomHeur.vnqbc
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.2CF9FC1
MicrosoftRansom:Win32/Cryptolocker.PDP!MTB
GDataGen:Variant.Graftor.681857
TACHYONRansom/W32.ShadowCryptor.350064
AhnLab-V3Trojan/Win32.FileCoder.C3574534
Acronissuspicious
McAfeeArtemis!346EC17A6D9F
MAXmalware (ai score=89)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Cryptolocker.R007C0DGP21
RisingRansom.ShadowCryptor!1.C536 (CLASSIC)
YandexTrojan.DelShad!rqJWuiNzwIM
IkarusPUA.ConvertAd
FortinetW32/GandCrab.G!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASRQA

How to remove Graftor.681857?

Graftor.681857 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment