Malware

Graftor.759918 removal guide

Malware Removal

The Graftor.759918 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.759918 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior

Related domains:

raw.githubusercontent.com

How to determine Graftor.759918?


File Info:

crc32: 34C6AC69
md5: 148924e56d431cfe73d6b7cc3a28c761
name: aaaaa.exe
sha1: f578aa3e2878bdf4988d1b3d9bef1e9b66e6bf42
sha256: b2b3ce039c5d3286265c60a680d151fdb0eeaba0b1476b0f16ad47c9bf267ba2
sha512: 29f5880d81094dcc211ef3658716d9cd446b7ec4c90da45125f8d95fd2fbdd66e793db59a550b0d3bc51b3117bff9f54c5114e7aa89438ea91863f45b82321c2
ssdeep: 12288:9aKgZ287X562OJ5ihpS5CzQ6KPhWgzN2J+SwBLZYRIcQxSvcWqv2fFdT4G:UKkpLcAhk5EZWhHN2dwhZuIcLN0G4G
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

ProgramID:
ProductName:
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0409 0x04e4

Graftor.759918 also known as:

MicroWorld-eScanGen:Variant.Graftor.759918
FireEyeGeneric.mg.148924e56d431cfe
McAfeeGenericRXAA-AA!148924E56D43
BitDefenderGen:Variant.Graftor.759918
Cybereasonmalicious.e2878b
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Graftor.759918
KasperskyHEUR:Trojan-GameThief.Win32.Worgtop.gen
RisingStealer.Growtopia!8.10A8D (RDMK:cmRtazqfc6Ragblq/W7n7HIbtlFm)
Ad-AwareGen:Variant.Graftor.759918
F-SecureHeuristic.HEUR/AGEN.1113038
DrWebTrojan.MulDrop12.44754
Invinceaheuristic
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Graftor.759918 (B)
IkarusTrojan-PSW.OnlineGames
JiangminTrojan.PSW.Worgtop.b
AviraHEUR/AGEN.1113038
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Graftor.DB986E
ZoneAlarmHEUR:Trojan-GameThief.Win32.Worgtop.gen
BitDefenderThetaGen:NN.ZexaF.34126.LmKfaWoSGNli
ALYacGen:Variant.Graftor.759918
MAXmalware (ai score=86)
MalwarebytesTrojan.GameThief
ESET-NOD32a variant of Win32/PSW.Growtopia.I
YandexTrojan.PWS.Growtopia!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Growtopia.I!tr.pws
AVGWin32:Trojan-gen
MaxSecureTrojan.Malware.78949831.susgen

How to remove Graftor.759918?

Graftor.759918 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment