Malware

How to remove “Graftor.744686”?

Malware Removal

The Graftor.744686 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.744686 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Graftor.744686?


File Info:

name: C0DFA74F186A986B7BBA.mlw
path: /opt/CAPEv2/storage/binaries/27c93000c88fc1919a0b54776e8d8ab151fe04b6dbb09057478681433cc270eb
crc32: C2BF0C67
md5: c0dfa74f186a986b7bba266c891f64b8
sha1: aec5430f0362e0a4304b879336a20e33e0eaf20e
sha256: 27c93000c88fc1919a0b54776e8d8ab151fe04b6dbb09057478681433cc270eb
sha512: 2423a0c8e8b79ed6f5038b6a05fb87567b165154ff08999ce4560b138780e45e732d158b17fefa96485be1cb1177e3344cb48aee17688d782af141b3ddeb7daa
ssdeep: 98304:1VW0lPyI7x2TPEbseZnPOk3W42oRATH6tfeo:1VW0lnEz+WmW4sTH6tGo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D569E03B243ACAFE52719765111977990EE9B31ED3E806FFB956C29C9B25F08BC7600
sha3_384: 1a474e7e6cf5d53ece8f2fab79de6db9d3e9707cc3def98a8cd5cec3f015b6bd92031866f6d0395688f29416ecfb7574
ep_bytes: 558bec6aff6838df970068d46d560064
timestamp: 2022-01-08 18:02:20

Version Info:

0: [No Data]

Graftor.744686 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.744686
FireEyeGeneric.mg.c0dfa74f186a986b
ALYacGen:Variant.Graftor.744686
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.744686
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.f186a9
BitDefenderThetaGen:NN.ZexaF.34182.@tW@aCetDepb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
KasperskyUDS:Backdoor.Win32.Poison.gen
APEXMalicious
Ad-AwareGen:Variant.Graftor.744686
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Graftor.744686 (B)
IkarusPUA.BlackMoon
GDataGen:Variant.Graftor.744686
JiangminTrojan.PSW.QQPass.ajv
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Graftor.DB5CEE
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!C0DFA74F186A
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.789972314
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazrmS9bcLY3lUz3ByI+7i3Gv)
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.65CA!tr

How to remove Graftor.744686?

Graftor.744686 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment