Malware

Graftor.717526 (file analysis)

Malware Removal

The Graftor.717526 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.717526 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.ip-adress.eu
pagead2.googlesyndication.com
www.venez.net
ipv4.adresse-ip.eu
venez.net
apps.identrust.com
crl.identrust.com
r3.o.lencr.org
www.jxngame.xyz

How to determine Graftor.717526?


File Info:

crc32: 19130187
md5: 3eb22b10b23b3293044e2243f5de9b3f
name: 3EB22B10B23B3293044E2243F5DE9B3F.mlw
sha1: a61e9363481299445f40a443cef8cb1c6bc2f7ce
sha256: 9dff5ff2e4390dd9c6580192ae0aba92bb86efd031277be1d299c5b22495ed3a
sha512: d3fd511b9e47963ebd8621c90812b60b5af0cd9991cf0f5ac5cc54548d744bd90d63e411a2b253be058ca32470aad715c2229c12b9ce0f6658ab86573a6f5e31
ssdeep: 3072:kqeCL4OALZOaqtDe1Pt1cVVrTWJ2XQkadcTGfSCwF+3wHgQ:lslOlS1PfCVuJYaiewFH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 3tttfdst
FileVersion: 1.03.0003
CompanyName: Steam
ProductName: Factorio
ProductVersion: 1.03.0003
OriginalFilename: 3tttfdst.exe

Graftor.717526 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.DownLoader23.809
ALYacGen:Variant.Graftor.717526
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.35941
AlibabaRansom:Win32/Blocker.a3c3c3c9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0b23b3
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jpmg
BitDefenderGen:Variant.Graftor.717526
NANO-AntivirusTrojan.Win32.Blocker.egtfzk
MicroWorld-eScanGen:Variant.Graftor.717526
TencentWin32.Trojan.Blocker.Loic
Ad-AwareGen:Variant.Graftor.717526
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
FireEyeGen:Variant.Graftor.717526
EmsisoftGen:Variant.Graftor.717526 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_68%
Antiy-AVLTrojan/Generic.ASMalwS.1BC8F99
KingsoftWin32.Heur.KVM006.a.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
GDataGen:Variant.Graftor.717526
McAfeeGeneric.asy
MAXmalware (ai score=84)
VBA32TrojanRansom.Blocker
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
YandexTrojan.GenAsa!UaMHfXysItI
IkarusTrojan.Blocker
MaxSecureTrojan.Malware.10110668.susgen
FortinetW32/Generic.AC.395E4C!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.717526?

Graftor.717526 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment