Malware

Graftor.787312 (file analysis)

Malware Removal

The Graftor.787312 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.787312 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.787312?


File Info:

crc32: BD2E707A
md5: 0fef0a8dad09da2ef65c4f5ce81676f5
name: 0FEF0A8DAD09DA2EF65C4F5CE81676F5.mlw
sha1: b2f35fafee965029c6cc00861ab69fff4fc7d3d9
sha256: 027e2d9d636b87979ff563a52e310e9d4e41c41cb24afbb6274221fc68044975
sha512: 77f2d82fec14aa861393d48d30648fc7de218b759799ff224d822374a1ba19cf3e764306e4ce2033bd83ceb48e1e55beac9c1d6d66fe181644abe478ea4a2259
ssdeep: 24576:3X9RGHtLe1zpu8MHjAnPd6UShTTI/ESl9DOqOm38t6:3YdXjSPkhTYT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.787312 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Onlinegames-9769428-0
FireEyeGeneric.mg.0fef0a8dad09da2e
McAfeeArtemis!0FEF0A8DAD09
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.787312
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.ChinDowl.gen
NANO-AntivirusTrojan.Win32.ChinDowl.iitebm
MicroWorld-eScanGen:Variant.Graftor.787312
RisingTrojan.Generic@ML.98 (RDML:dJPz+KoUA2jfzbNNK5M5oQ)
Ad-AwareGen:Variant.Graftor.787312
SophosGeneric PUA LC (PUA)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftGen:Variant.Graftor.787312 (B)
IkarusPUA.BlackMoon
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojanDownloader:Win32/Emotet!ml
ArcabitTrojan.Graftor.DC0370
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.ChinDowl.gen
GDataGen:Variant.Graftor.787312
BitDefenderThetaGen:NN.ZexaF.34804.2rW@aS1p@sob
ALYacGen:Variant.Graftor.787312
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R035H0CB221
TencentWin32.Trojan-downloader.Chindowl.Lad
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/QQPass.ELG!tr.pws
Cybereasonmalicious.dad09d
MaxSecureTrojan.Malware.300983.susgen

How to remove Graftor.787312?

Graftor.787312 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment