Malware

Graftor.858268 malicious file

Malware Removal

The Graftor.858268 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.858268 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Graftor.858268?


File Info:

crc32: 7B3B5B09
md5: a251fb0d51798162bc494dacaadf52d5
name: A251FB0D51798162BC494DACAADF52D5.mlw
sha1: ce52a0e40711478735265199c65ade709fbad5a0
sha256: 04119810b3de63a41768108b80244f50f84e8938437d117e4b25c47856143fde
sha512: ae87794d4f0902bb22180a84ce5f9a6ec0572ef45aab63be993486b73b71822c91efa503fc59d5a791a85478a1f22d24786aec554034fb593807f204cc167f11
ssdeep: 24576:SJixHxdNUI99cVskKsaBukTAvxuPxgbsLeFDWMVY3:ewRdaskESxUuoLeIx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e94x884cx6563x4ebax3014yemao.vipx3015 x7248x6743x6240x6709
FileVersion: 1.0.2.0
CompanyName: x4e94x884cx6563x4ebax3014yemao.vipx3015
Comments: Tianyancha VIP Nexonplug
ProductName: Tianyancha VIP Nexonplug
ProductVersion: 1.0.2.0
FileDescription: Tianyancha VIP Nexonplug
Translation: 0x0804 0x04b0

Graftor.858268 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.858268
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Graftor.858268
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.d51798
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
MicroWorld-eScanGen:Variant.Graftor.858268
Ad-AwareGen:Variant.Graftor.858268
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34678.0r0@aKzZOsgb
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.a251fb0d51798162
EmsisoftGen:Variant.Graftor.858268 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Graftor.DD189C
GDataGen:Variant.Graftor.858268
Acronissuspicious
McAfeeArtemis!A251FB0D5179
MAXmalware (ai score=89)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.65CA!tr
Paloaltogeneric.ml

How to remove Graftor.858268?

Graftor.858268 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment