Malware

Graftor.976474 removal tips

Malware Removal

The Graftor.976474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.976474 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.2ip.ua
dgos.top
astdg.top
sergeevih43.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Graftor.976474?


File Info:

crc32: 7FB49682
md5: 20a2ca12be8a22b5bf51cf214fc8043e
name: 20A2CA12BE8A22B5BF51CF214FC8043E.mlw
sha1: 43fb0496649995ba9c6bcaa196f5e8709f9046ba
sha256: fc5d708f8f525edae1dcf013ce022de43886a3d49c3d79e6693653c10bf0bc5a
sha512: 0aaa0d0e24e1f6954cdf9874a983dda6e0ab41948d9fe505dcc161d2784837616afb4fa89215625f1ad5919eebd28062d2678ae42266301a44d4e81a4e1d2db4
ssdeep: 12288:IpAlruI7Ps7zvh+9g9DEnYP/nL4jux2NvKlrzzBODYnIlsu22t0WXgzbn:IkuI7TIDbHkjuUvYHgkHARXgvn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020a 0x0547

Graftor.976474 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.664999
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyUDS:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Graftor.976474
MicroWorld-eScanGen:Variant.Graftor.976474
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34790.0uW@a4sgLmhG
McAfee-GW-EditionBehavesLike.Win32.Lockbit.cc
FireEyeGeneric.mg.20a2ca12be8a22b5
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Glupteba!ml
GDataGen:Variant.Graftor.976474
Acronissuspicious
MAXmalware (ai score=84)
VBA32BScope.Trojan.Crypt
MalwarebytesTrojan.Glupteba
RisingTrojan.Kryptik!1.D7E8 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:PWSX-gen [Trj]
Qihoo-360HEUR/QVM10.1.801B.Malware.Gen

How to remove Graftor.976474?

Graftor.976474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment