Malware

Graftor.836296 (B) removal instruction

Malware Removal

The Graftor.836296 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.836296 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.836296 (B)?


File Info:

crc32: 851167B4
md5: 596c6a0a7e78f71083bd371ff3ae4c55
name: upload_file
sha1: ea0fe079261e2056fc0dbcdc8f24166cb7a6685e
sha256: 3c0957a9229442cae275329702b10d3a3045b1c666b00f0f67c4502fa4abe9d4
sha512: 93b8b3a209a531c9ede477ca0410548b9e06efbfa449cf8aa70568fa5ffc5a7b8c1bc3c0908f1c1743f284b16a9a213d276bb34b2b09ed9735e26f6e052afc4c
ssdeep: 24576:XlEuzpFz38+MITTmC8TgIFra34WM3k/tj:XWmtsCT78433M3w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Co;;pk 65rftakire Corp.
InternalName:
FileVersion: 6f0
CompanyName: Brlan4hbbge Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 6z335.0
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Graftor.836296 (B) also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Graftor.836296
FireEyeGeneric.mg.596c6a0a7e78f710
CAT-QuickHealTrojan.DriveHide.VN8
Qihoo-360HEUR/QVM05.1.A457.Malware.Gen
McAfeePWS-FCRZ!596C6A0A7E78
K7AntiVirusTrojan ( 005711ca1 )
BitDefenderGen:Variant.Graftor.836296
K7GWTrojan ( 005711ca1 )
Cybereasonmalicious.9261e2
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Crypt.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
Ad-AwareGen:Variant.Graftor.836296
EmsisoftGen:Variant.Graftor.836296 (B)
F-SecureTrojan.TR/Injector.fmcls
DrWebBackDoor.SpyBotNET.25
InvinceaMal/Generic-S
McAfee-GW-EditionPWS-FCRZ!596C6A0A7E78
IkarusWin32.Outbreak
AviraTR/Injector.fmcls
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.D3!ml
ArcabitTrojan.Graftor.DCC2C8
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataGen:Variant.Graftor.836296
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZelphiF.34570.cH0@aace@Mii
ALYacGen:Variant.Graftor.835474
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Injector.ENQF
RisingTrojan.Injector!8.C4 (TFE:5:g4c0RMnu8HH)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/GenKryptik.EUGR!tr
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Graftor.836296 (B)?

Graftor.836296 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment