Malware

Graftor.948627 malicious file

Malware Removal

The Graftor.948627 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.948627 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.948627?


File Info:

crc32: A9CC5402
md5: ea04caeaf9c75ea51f23c2039c939f90
name: EA04CAEAF9C75EA51F23C2039C939F90.mlw
sha1: f1564fd4d61072a3c47c1b8e6411cdfeacbc67c0
sha256: b1491d120c666356b3fe3058f8fbc7178cc4e1fea2ef63b8d4810fb78eac48ad
sha512: 25a68a080c86f659ebb336abfafc28b88add37146ce30ca378cfbe97c5ed889892c8e229e55e606b2d2d42bb9e1877667dce9b36e5e49da9546632bcc1e5251f
ssdeep: 3072:XCB5uuP/lsonqmYmm3WBbd4M57WuLnYk3/QxkgBbd4M5C:Xiuu3lPlYukQnh+kAQ
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Graftor.948627 also known as:

K7AntiVirusTrojan ( 00576fb91 )
LionicTrojan.Win32.Graftor.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.948627
CylanceUnsafe
ZillyaTrojan.Copak.Win32.33288
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.74c8194d
K7GWTrojan ( 00576fb91 )
Cybereasonmalicious.4d6107
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Packed.Copak-9853643-0
KasperskyTrojan.Win32.Copak.ebcn
BitDefenderGen:Variant.Graftor.948627
NANO-AntivirusTrojan.Win32.PackedENT.imwxeg
MicroWorld-eScanGen:Variant.Graftor.948627
TencentMalware.Win32.Gencirc.10ce5924
Ad-AwareGen:Variant.Graftor.948627
SophosMal/Generic-R + Troj/Agent-BGZJ
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34266.lmZ@aqxLbnk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R049C0PGN21
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
FireEyeGen:Variant.Graftor.948627
EmsisoftGen:Variant.Graftor.948627 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.guyux
AviraTR/Patched.Ren.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare/Win32.Tampering.s
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ArcabitTrojan.Graftor.DE7993
ZoneAlarmTrojan.Win32.Copak.ebcn
GDataGen:Variant.Graftor.948627 (2x)
AhnLab-V3Malware/Win32.Generic.R369371
McAfeeGenericRXOA-CF!EA04CAEAF9C7
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0PGN21
RisingTrojan.Injector!1.C865 (CLASSIC)
IkarusTrojan.Kryptik
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Graftor.948627?

Graftor.948627 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment