Malware

Graftor.942016 information

Malware Removal

The Graftor.942016 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.942016 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Arabic (Algeria)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.942016?


File Info:

crc32: 7CC69B2D
md5: 93c590f17fd7310f69fc266be2261a4a
name: 93C590F17FD7310F69FC266BE2261A4A.mlw
sha1: d329be2850d79ee7ec267dbd156d335f9792fd19
sha256: 5fc3d7168643f62e68945d12cdd1516bce7d92bd2cd52b779023baff564d5b93
sha512: 022c5c55e9f0355d9dffa9e187a6c6c36572f154a8506e99881d0eb0dd18bb47973d8033bbe9b7800be3fed74d7a1d76f7a5f6644cb41a0eaf01dfb79894e2ff
ssdeep: 98304:zviz/27qWGq/TzuqCDl2Ptao7jymaiNs:zviq75/TzuftANs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.9600.16428 (winblue_gdr.131013-1700)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16428
FileDescription: x200ex200ex627x644x627x633x62ax62ex631x627x62c x627x644x630x627x62ax64a x644x645x644x641 x62ex632x627x646x629 Win32
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0401 0x04b0

Graftor.942016 also known as:

DrWebTrojan.DownLoader26.31224
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.942016
SangforBackdoor.MSIL.SpyGate.whk
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.17fd73
CyrenDropper.BJYT
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RVD
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-6895514-0
KasperskyBackdoor.MSIL.SpyGate.whk
BitDefenderGen:Variant.Graftor.942016
NANO-AntivirusTrojan.Win32.SpyGate.exkwur
MicroWorld-eScanGen:Variant.Graftor.942016
TencentMsil.Backdoor.Spygate.Hufl
Ad-AwareGen:Variant.Graftor.942016
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Emotet.wc
FireEyeGeneric.mg.93c590f17fd7310f
EmsisoftGen:Variant.Graftor.942016 (B)
AviraTR/AD.Bladabindi.ckfhg
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Graftor.942016
McAfeeArtemis!93C590F17FD7
MAXmalware (ai score=82)
MalwarebytesTrojan.Dropper.MSI.Generic
YandexTrojan.Igent.bT7Ssp.42
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RVD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.942016?

Graftor.942016 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment