Malware

How to remove “Graftor.849866”?

Malware Removal

The Graftor.849866 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.849866 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
darkangel.ac.ug
brice.ac.ug
apps.identrust.com
puffpuff423.top

How to determine Graftor.849866?


File Info:

crc32: 6357E491
md5: 7da845a5f52888d10082d83808e57376
name: 7DA845A5F52888D10082D83808E57376.mlw
sha1: 37761cc45c10940f3c9ab2d6f48ca33deab126e3
sha256: 13383a95305773d0defdd99d9d5d555eb72d8bea2265b44f133c56ffbdae2289
sha512: a130bf77c66a3f32478a7f7c02fe9c9a628ae68e13aeb52decad3d145c417945d0332dbd722e8795c91554b58a46b0e0fe1896c61b9be770d9ed3a09ce8d3275
ssdeep: 24576:Abs50MO2RrtrfieDcGf+4Tx70JzQs50MJCwtO6s50MQcpHuPiq:Us5dkeE4TxMQs5/w6s5RHyiq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: 44rq3dfeawdesf777
FileVersion: 1.00
OriginalFilename: 44rq3dfeawdesf777.exe
ProductName: CosmosTheGreatAwakening777

Graftor.849866 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.42634
MicroWorld-eScanGen:Variant.Graftor.849866
FireEyeGeneric.mg.7da845a5f52888d1
McAfeeGenericRXMQ-UL!7DA845A5F528
K7AntiVirusTrojan ( 005720621 )
BitDefenderGen:Variant.Graftor.849866
K7GWTrojan ( 005720621 )
Cybereasonmalicious.45c109
AvastWin32:PWSX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareGen:Variant.Graftor.849866
EmsisoftTrojan.Injector (A)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionGenericRXMQ-UL!7DA845A5F528
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Graftor.DCF7CA
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Graftor.849866
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R354530
ALYacGen:Variant.Graftor.849866
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Injector.ENSO
RisingTrojan.Injector!1.C6AF (CLASSIC)
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.ENLK!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM20.1.9907.Malware.Gen

How to remove Graftor.849866?

Graftor.849866 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment