Malware

Should I remove “Graftor.Azorult.634538”?

Malware Removal

The Graftor.Azorult.634538 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.Azorult.634538 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.Azorult.634538?


File Info:

name: 6A49EC3B34BD05204819.mlw
path: /opt/CAPEv2/storage/binaries/694a111d2079017800cef2b7978af448b3d749cb4c2bc5aeeb1a5de83f174d90
crc32: D570B574
md5: 6a49ec3b34bd0520481966948c6027ec
sha1: 6f1f29bc420210eefc6006f9a2589a32f1d19655
sha256: 694a111d2079017800cef2b7978af448b3d749cb4c2bc5aeeb1a5de83f174d90
sha512: 3a87fb1d71ef2c664b4e4c4711086bbcd8b131ebfad1581284a25c74e1830daee60db46757a5cbc57afe99d0ba0bd832404e29792fe1f1146d6aaba304ddb7b0
ssdeep: 12288:tO6f22/Ug3pAeullxZiiXpVVtZOWaCwsv:tOHw3Z+xZtVHljwA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA945C37E6D0C437D123197CDC5B9AF8A929BE50E92868472EE83D4C7F397817825293
sha3_384: a50fc1f6fce4d6a654dfba40d43b97091be8ba630be2a20d364c24335bf47a7215492877285e1198131280730d0ed41d
ep_bytes: 558bec83c4f0b80c304500e87830fbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.Azorult.634538 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.Azorult.634538
FireEyeGeneric.mg.6a49ec3b34bd0520
ALYacGen:Variant.Graftor.Azorult.634538
Cylanceunsafe
ZillyaTrojan.Injector.Win32.653268
K7AntiVirusTrojan ( 00557fc81 )
AlibabaTrojan:Win32/RemcosCrypt.615db114
K7GWTrojan ( 00557fc81 )
Cybereasonmalicious.b34bd0
ArcabitTrojan.Graftor.Azorult.D9AEAA
BitDefenderThetaGen:NN.ZelphiF.36308.AGY@auhBBKhk
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EHVL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
BitDefenderGen:Variant.Graftor.Azorult.634538
NANO-AntivirusTrojan.Win32.Graftor.hotewf
TencentWin32.Trojan.FalseSign.Vgil
SophosMal/Generic-S
VIPREGen:Variant.Graftor.Azorult.634538
McAfee-GW-EditionFareit-FZO!6A49EC3B34BD
EmsisoftGen:Variant.Graftor.Azorult.634538 (B)
AviraTR/Injector.tesmb
Antiy-AVLTrojan/Win32.Casur
MicrosoftTrojan:Win32/RemcosCrypt.ACH!MTB
GDataGen:Variant.Graftor.Azorult.634538
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3511000
McAfeeFareit-FZO!6A49EC3B34BD
MAXmalware (ai score=82)
MalwarebytesGeneric.Trojan.Injector.DDS
ZonerTrojan.Win32.83223
RisingTrojan.Kryptik!1.C56D (CLASSIC)
YandexTrojan.Injector!NsZoNs1RF8Y
IkarusTrojan-Dropper.Win32.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.EKLE!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.Azorult.634538?

Graftor.Azorult.634538 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment