Malware

About “Graftor.758772” infection

Malware Removal

The Graftor.758772 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.758772 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.softinterface.com
www.bing.com
ocsp.comodoca.com
ocsp.usertrust.com

How to determine Graftor.758772?


File Info:

crc32: 4E11EE33
md5: e0d2cc4a83265968b31a9602a174f081
name: E0D2CC4A83265968B31A9602A174F081.mlw
sha1: 165196426278959d7464da0c285c4a7e5997fecd
sha256: 83d222d1e5851840b5fcf0abeb2e580c1c8659b3125d7c1136807871ccad2085
sha512: 32b729e23387c01f44c898ecff29b3fa6932cce392ee7158f8e59c5b8953bf5bdd0050aacb07b87cda589755d713e644a9152d23e233b6ab940312ee3ef4739c
ssdeep: 24576:nNX2SvphwVQqH5hHUsT/jmxjG8UKmwPLXwWvQCERYqqyl71vNBRnd9jduwNZR3M6:NGUpu6qHEcqG8JhLAWvQCER4yl795nDl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright, SoftInterface 1999-2020
InternalName: ConvertXLS
FileVersion: 13.07.0002
CompanyName: www.SoftInterface.COM
LegalTrademarks: Softinterface, Inc.
Comments: Created by www.SoftInterface.COM
ProductName: 'Convert XLS'
OLESelfRegister:
ProductVersion: 13.07.0002
FileDescription: The Comprehensive Excel Conversion Utility
OriginalFilename: ConvertXLS.exe

Graftor.758772 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004beeaf1 )
LionicRiskware.Win32.Malicious.1!c
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.758772
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaPacked:Win32/EnigmaProtector.c5d9e7cb
K7GWTrojan ( 004beeaf1 )
Cybereasonmalicious.a83265
CyrenW32/SysVenFak.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Bladabindi-9854975-0
BitDefenderGen:Variant.Graftor.758772
MicroWorld-eScanGen:Variant.Graftor.758772
Ad-AwareGen:Variant.Graftor.758772
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34294.Dz1@aym6UTci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.e0d2cc4a83265968
EmsisoftGen:Variant.Graftor.758772 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.C669
MicrosoftPUA:Win32/Vigua.A
GDataGen:Variant.Graftor.758772
McAfeeArtemis!E0D2CC4A8326
MAXmalware (ai score=84)
VBA32Backdoor.Bladabindi
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.758772?

Graftor.758772 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment