Malware

Should I remove “Graftor.738780”?

Malware Removal

The Graftor.738780 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.738780 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.738780?


File Info:

crc32: B0293577
md5: c247031995fd43b6878e3996780df3ad
name: Documents_pdf.exe
sha1: eb47fa6358d920c716ab7c2bacd7f9b57cc702d1
sha256: 766933a463a302a8c4553ce1e7e39f058358395ae65f0d987ef4a2331dd29bbc
sha512: e781601c65e851b613da0e486e7ed3e513572fd6b058d57de2758ac013a2f4757c4fe50c3ae79abab5920f15c6783b4e4086dd124cddd512f2a1634396109eae
ssdeep: 768:QW9yZKNHcqjvxquVEf1z5iQ0mc+aI9CHEmzX77PMST4yDu0HpfHC:RsKNHflqu0z5iQC+asY29
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: capti
FileVersion: 2.06
CompanyName: KEYstore
Comments: KEYstore
ProductName: Nousfreds5
ProductVersion: 2.06
OriginalFilename: capti.exe

Graftor.738780 also known as:

MicroWorld-eScanGen:Variant.Graftor.738780
ALYacGen:Variant.Graftor.738780
BitDefenderGen:Variant.Graftor.738780
TrendMicroTROJ_GEN.R015C0DDS20
BitDefenderThetaGen:NN.ZevbaCO.34108.fm0@aSjJh!mi
F-ProtW32/VBKrypt.AJI.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.ELPV
TrendMicro-HouseCallTROJ_GEN.R015C0DDS20
GDataGen:Variant.Graftor.738780
KasperskyHEUR:Trojan.Win32.NetWire.vho
AlibabaTrojan:Win32/Injector.32f49822
Ad-AwareGen:Variant.Graftor.738780
EmsisoftGen:Variant.Graftor.738780 (B)
F-SecureTrojan.TR/Injector.rwrti
Invinceaheuristic
McAfee-GW-EditionFareit-FSJ!C247031995FD
SophosMal/FareitVB-AC
APEXMalicious
CyrenW32/VBKrypt.AJI.gen!Eldorado
AviraTR/Injector.rwrti
ArcabitTrojan.Graftor.DB45DC
AhnLab-V3Trojan/Win32.VBKrypt.R334502
ZoneAlarmHEUR:Trojan.Win32.NetWire.vho
MicrosoftTrojanSpy:Win32/FormBook.AR!MTB
McAfeeFareit-FSJ!C247031995FD
MAXmalware (ai score=84)
MalwarebytesTrojan.Injector
RisingTrojan.Injector!1.C5BD (CLASSIC)
YandexTrojan.Igent.bTC5AI.9
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_98%
FortinetW32/GuLoader.VHIM!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.483

How to remove Graftor.738780?

Graftor.738780 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment