Malware

Graftor.Elzob.25220 information

Malware Removal

The Graftor.Elzob.25220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.Elzob.25220 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

www.315caipiao.com
redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com

How to determine Graftor.Elzob.25220?


File Info:

crc32: 925E5C6A
md5: 35edbdc6ea46655214b796087b0a2100
name: upload_file
sha1: feadb4501a6e195177c2e4a0a6e34b2146ce4434
sha256: 24b4070f16d73655216b783a414e67a9fe6c202b21e41a10b17f992110ada5d1
sha512: b9ce83e03dedfde1e2bb923fbfc41f40c64185e04cf9faccdf775922ce565887d19a2d1b51fc7591f1cd0f30f240e998ae11cd8398d8a24e00eaa7bb33d130c1
ssdeep: 3072:WYtWdbDGqQlJhAc7MMejEhlN6gCJfZNzp9+X6:WYtWdbajJSUtzN6pfLz6X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2005-2012
InternalName: install
FileVersion: 4, 2, 6, 0
CompanyName: NetSoft Studio
PrivateBuild: 20120928.01
LegalTrademarks:
Comments:
ProductName: P2Px7ec8x7ed3x8005
SpecialBuild:
ProductVersion: 4, 2, 6, 0
FileDescription: P2Px7ec8x7ed3x8005x4e3bx7a0bx5e8f
OriginalFilename: p2pover.EXE
Translation: 0x0804 0x04b0

Graftor.Elzob.25220 also known as:

MicroWorld-eScanGen:Variant.Graftor.Elzob.25220
FireEyeGeneric.mg.35edbdc6ea466552
CAT-QuickHealTrojan.Zegost.KK6
ALYacGen:Variant.Graftor.Elzob.25220
ZillyaTrojan.Jorik.Win32.191789
SangforMalware
K7AntiVirusTrojan ( 004e8ca91 )
BitDefenderGen:Variant.Graftor.Elzob.25220
K7GWTrojan ( 004e8ca91 )
Cybereasonmalicious.6ea466
Invinceaheuristic
BaiduWin32.Trojan.Farfli.aw
F-ProtW32/A-57c46d8b!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Tnega.ASAM
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Trojan.837453-1
GDataGen:Variant.Graftor.Elzob.25220
KasperskyTrojan.Win32.Jorik.Zegost.kkf
AlibabaTrojan:Win32/Jorik.5e8fbc2b
NANO-AntivirusTrojan.Win32.Jorik.brnurt
ViRobotTrojan.Win32.Jorik.135168.A
RisingTrojan.Farfli!8.FF (TFE:2:1y5zgRyQQHP)
Ad-AwareGen:Variant.Graftor.Elzob.25220
EmsisoftGen:Variant.Graftor.Elzob.25220 (B)
ComodoTrojWare.Win32.Trojan.Agent.Gen@4thdue
F-SecureBackdoor.BDS/Farfli.pzmnau
DrWebTrojan.DownLoader8.2062
VIPRETrojan.Win32.Zegost.lt (v)
McAfee-GW-EditionGenericR-DUT!35EDBDC6EA46
MaxSecureTrojan.Malware.5164564.susgen
SophosTroj/Jorik-AP
IkarusTrojan.Win32.KillAV
CyrenW32/A-57c46d8b!Eldorado
JiangminHeur:Trojan/Agent
WebrootW32.Malware.Gen
AviraBDS/Farfli.pzmnau
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Zegost
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.Elzob.D6284
ZoneAlarmTrojan.Win32.Jorik.Zegost.kkf
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.Jorik.C165073
Acronissuspicious
McAfeeGenericR-DUT!35EDBDC6EA46
VBA32Trojan.Zegost
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Farfli.UO
YandexTrojan.Zegost!ci9RlCL7I/U
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/Jorik_Zegost.KEC!tr
BitDefenderThetaGen:NN.ZexaF.33558.iy0@aidLfBij
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Backdoor.Win32.Agent.DY

How to remove Graftor.Elzob.25220?

Graftor.Elzob.25220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment