Malware

Should I remove “Graftor.879456”?

Malware Removal

The Graftor.879456 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.879456 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com
blacksmokegun.top
marianne.ac.ug
dancedance.ac.ug

How to determine Graftor.879456?


File Info:

crc32: 62C5A1A6
md5: 5af062f1cde00f04809a212a60017187
name: 5AF062F1CDE00F04809A212A60017187.mlw
sha1: ad6edd457e934cf3eafd1866b845b2f684f0a174
sha256: 69281664db9f7088a1cdfbf5b3468170bdbeadeb3ce9f4db3ef114ef8828e870
sha512: d4b6f7479d21146ed14444937ceb07e34507aa78062955de8aa4d10323908083641fa910843528d651c08b42bff6b32ef3b636e40c71563ed110b4c219c0e32f
ssdeep: 24576:QQCemrx/IW4tfPmeuBO4GPDRwrbrtJerRMYEa0wz7UOX1hIVeoo8:QQCemrxw7IGPDRw3r7fYEa0wMOlhIVe+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: Ersmslfksepomvdmnf222
FileVersion: 1.00
OriginalFilename: Ersmslfksepomvdmnf222.exe
ProductName: Nxedsdcxsewaedea

Graftor.879456 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.879456
FireEyeGeneric.mg.5af062f1cde00f04
CAT-QuickHealTrojan.Multi
McAfeeGenericRXNL-JS!5AF062F1CDE0
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057680d1 )
BitDefenderGen:Variant.Graftor.879456
K7GWTrojan ( 0057680d1 )
Cybereasonmalicious.1cde00
BitDefenderThetaGen:NN.ZevbaF.34780.gn2@aKfxdsF
CyrenW32/Trojan.GNOJ-6840
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Chapak.eysk
AlibabaTrojan:Win32/Chapak.59d691d0
ViRobotTrojan.Win32.Z.Injector.1157312
AegisLabTrojan.Win32.Chapak.4!c
TencentWin32.Trojan.Falsesign.Tafg
Ad-AwareGen:Variant.Graftor.879456
EmsisoftGen:Variant.Graftor.879456 (B)
ComodoMalware@#2dxxlexnby84
F-SecureTrojan.TR/Injector.qyerc
DrWebTrojan.VbCrypt.250
TrendMicroTROJ_GEN.R002C0WAQ21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
AviraTR/Injector.qyerc
KingsoftWin32.Troj.Chapak.ey.(kcloud)
MicrosoftTrojan:Win32/Stimilina
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Graftor.DD6B60
ZoneAlarmTrojan.Win32.Chapak.eysk
GDataGen:Variant.Graftor.879456
CynetMalicious (score: 100)
VBA32Trojan.VBKrypt
MAXmalware (ai score=85)
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EOFI
TrendMicro-HouseCallTROJ_GEN.R002C0WAQ21
RisingTrojan.Injector!1.C6AF (CLASSIC)
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/EOFI!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.878

How to remove Graftor.879456?

Graftor.879456 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment