Malware

Graftor.792656 (B) removal tips

Malware Removal

The Graftor.792656 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.792656 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Unusual version info supplied for binary
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.792656 (B)?


File Info:

crc32: BB9834FE
md5: 30ce1afa7e522716724f32b0bf814908
name: 30CE1AFA7E522716724F32B0BF814908.mlw
sha1: 4db62f647fc165a69e881cf412d929af0887e01d
sha256: ba3a54f9578a93cd46b98aacaddacbc63f426c7662efd79327a54200ddeaeb31
sha512: fecf3868c9fde3867c142a25c32d7ebca8755ae70d17ff330f67e80110fe15e7401ef531d95bc047289f179bd4bc4eba653652037ad11a41926fc8d29ab9658d
ssdeep: 12288:GIIRidPi4+KMMOl8mbhVCgQTFcuE8mh0W9G8o5fdPACbLjmpoM7OW1CUqc:11k4IEgQxJrrACPjmpoKOuCUqc
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Microsoft x66f4x65b0x72ecx7acbx7a0bx5e8fx5305 x5728x7ebfx66f4x65b0x5de5x5177
FileVersion: 20.21.5.18
CompanyName: Bgrc
Comments: x9002x7528x4e8ex64 1909
ProductName: x8865x4e01x66f4x65b0x5de5x5177
ProductVersion: 20.21.5.18
FileDescription: Microsoft hotfix x4e0bx8f7dx66f4x65b0x7a0bx5e8f
Translation: 0x0804 0x04b0

Graftor.792656 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader39.18031
CynetMalicious (score: 100)
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Graftor.792656
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/MiscX.f473804d
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a7e522
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:MiscX-gen [PUP]
ClamAVWin.Malware.Zusy-6809753-0
BitDefenderGen:Variant.Graftor.792656
MicroWorld-eScanGen:Variant.Graftor.792656
Ad-AwareGen:Variant.Graftor.792656
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34690.LmLfaCa5Srob
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.30ce1afa7e522716
EmsisoftGen:Variant.Graftor.792656 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.792656
Acronissuspicious
McAfeeArtemis!30CE1AFA7E52
MAXmalware (ai score=82)
MalwarebytesMalware.AI.2263509960
TrendMicro-HouseCallTROJ_GEN.R005H09EI21
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazorLrAlZNEdCuzwrjml7N1S)
YandexTrojan.DL.Agent!It5I7/Hs/0A
IkarusTrojan.Win32.CoinMiner
FortinetRiskware/Application
AVGWin32:MiscX-gen [PUP]
Paloaltogeneric.ml

How to remove Graftor.792656 (B)?

Graftor.792656 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment