Malware

Should I remove “Graftor.689280 (B)”?

Malware Removal

The Graftor.689280 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.689280 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.689280 (B)?


File Info:

crc32: 42D9C96C
md5: 4287356f0d03dfa1ef6bd748c7274713
name: 4287356F0D03DFA1EF6BD748C7274713.mlw
sha1: dcc912a89f69c2e3addff7b195913ef51a62d9e7
sha256: 043215a0c8ff897f2327528f3d7a3e90c563526d5a03b7cb234db8820370cab6
sha512: 9d1c9b3e0496b247a17e4f78038acae1e6ab1ec2403da1ed1df5e5943901b5a11679b1e19f009bcd0d52e9328000fc39316a7bc25c5b4088372c23451bab6020
ssdeep: 24576:iU8EJb2/Z71VWBXCSRkjxCx3Yus+D66AbxusHq2dfhGR2XYuBbhRoo1KuggGFmbt:7NJb0fcdD6LAENZTXYuB/oo1KHMKU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: AWei x6c49x5316x5de5x4f5cx5ba4
Comments: xb4xcbxb0xb2xd7xb0xb3xccxd0xf2xd3xc9 Inno Setup xb9xb9xbdxa8xa1xa3
ProductName: Textify
ProductVersion: 1.8.2
FileDescription: Textify Setup
OriginalFileName:
Translation: 0x0804 0x0000

Graftor.689280 (B) also known as:

MicroWorld-eScanGen:Variant.Graftor.689280
ZillyaTrojan.Generic.Win32.949955
CrowdStrikewin/malicious_confidence_60% (W)
APEXMalicious
GDataGen:Variant.Graftor.689280
BitDefenderGen:Variant.Graftor.689280
BitDefenderThetaGen:NN.ZexaF.34104.2yZ@a4IhYzfG
McAfee-GW-EditionBehavesLike.Win32.Ramnit.tc
FireEyeGen:Variant.Graftor.689280
EmsisoftGen:Variant.Graftor.689280 (B)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.C!ml
JiangminTrojan.Zenpak.azu
ArcabitTrojan.Graftor.DA8480
AegisLabTrojan.Win32.Graftor.4!c
MAXmalware (ai score=80)
RisingMalware.Heuristic!ET#82% (RDMK:cmRtazoksgYW+y1NLhyrb5ijB444)
Paloaltogeneric.ml

How to remove Graftor.689280 (B)?

Graftor.689280 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment