Malware

Graftor.713212 information

Malware Removal

The Graftor.713212 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.713212 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Graftor.713212?


File Info:

crc32: AC01A0A8
md5: fc273bca0b067eb3636ce5a2381c5b9e
name: FC273BCA0B067EB3636CE5A2381C5B9E.mlw
sha1: bcde067f3bd32b04b2aaa32d3ac61fc3fbd31dc2
sha256: 3cd73712de421856663b567f8cbaffb513f0cc43918642b8db21fba227b42b6a
sha512: 4a9ee25dd67189b8cf1e347648c9a98b27354684b8a702ddbad141ca108a1710fb120643a07109806d41431818fc5bd5b507fdc635e5725fb02023c615722932
ssdeep: 24576:k7VQByhFd+4tkojNmf9WcDag3EoAxYM966gmHG:yhbdm1Z3EvxYMgj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2007-2015 United Technologies
InternalName: Govind Interfering
FileVersion: 2.3.2.5
CompanyName: United Technologies
PrivateBuild: 2.3.2.5
LegalTrademarks: (C) 2007-2015 United Technologies
ProductName: Govind Interfering
ProductVersion: 2.3.2.5
FileDescription: Conditioning Hardwired Prtnet
OriginalFilename: Govind Interfering.exe
Translation: 0x0409 0x04b0

Graftor.713212 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00560b6f1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
CynetMalicious (score: 99)
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
ZillyaTrojan.DelShad.Win32.412
SangforTrojan.Win32.Agent.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/DelShad.ea288c28
K7GWTrojan ( 00560b6f1 )
Cybereasonmalicious.a0b067
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBEK
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.DelShad.cpl
BitDefenderGen:Variant.Graftor.713212
NANO-AntivirusTrojan.Win32.DelShad.hbeqzy
MicroWorld-eScanGen:Variant.Graftor.713212
TencentWin32.Trojan.Delshad.Ednj
Ad-AwareGen:Variant.Graftor.713212
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.3q0@a4!Hiugi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.fc273bca0b067eb3
EmsisoftGen:Variant.Graftor.713212 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.DelShad.td
WebrootW32.Trojan.Gen
AviraTR/AD.Crysis.bikix
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2FFDA32
MicrosoftTrojan:Win32/Occamy.C3C
GDataGen:Variant.Graftor.713212
McAfeeArtemis!FC273BCA0B06
MAXmalware (ai score=84)
VBA32BScope.TrojanPSW.Racealer
PandaTrj/RansomCrypt.K
TrendMicro-HouseCallMal_HPGen-37b
RisingTrojan.Generic@ML.82 (RDMK:B6FA+w6cgFXo/smJQBRzHw)
YandexTrojan.Kryptik!kNUYsthInTc
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74837539.susgen
FortinetW32/DelShad.CPL!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Graftor.713212?

Graftor.713212 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment