Trojan

Trojan.Graftor malicious file

Malware Removal

The Trojan.Graftor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Graftor virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Graftor?


File Info:

crc32: 382DB14E
md5: 7ff1341515df5d4e94d79a7ec9c27de4
name: 7FF1341515DF5D4E94D79A7EC9C27DE4.mlw
sha1: 0e0ae86fa36956c2c7fe911e8980271b46725e92
sha256: bd0576903d404f4917fb5cb4a85c91f36203bb6ed96d0ac7ca6c5c742622e3ff
sha512: 0793addf193750d809c56f99a95cb94eadeb2d366f93ea3798c60a67fcd701745d8f3890310ffe8623cba5dc94753715bdcb001d4590d12c679a13dd13607a03
ssdeep: 12288:gA4F2tDgMpfq46ak8ZhI7KLHbSy3AWJ6+j3iBRIF8H:wFCDgMpfq4e8ZhmdyQkyYF8H
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: eijfozief.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: eijfozief.exe
Translation: 0x040c 0x04b0

Trojan.Graftor also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050b3aa1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Cerber.311
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.4191
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0050b3aa1 )
Cybereasonmalicious.515df5
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.DNRI
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Razy-6996978-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Cerber.311
NANO-AntivirusTrojan.Win32.Zerber.enptvt
MicroWorld-eScanGen:Variant.Ransom.Cerber.311
TencentWin32.Trojan.Generic.Anzt
Ad-AwareGen:Variant.Ransom.Cerber.311
SophosMal/Cerber-AB
ComodoMalware@#3nbi31euzsbf4
BitDefenderThetaGen:NN.ZexaF.34050.Iq1@a4Fyb2jm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.drb
FireEyeGeneric.mg.7ff1341515df5d4e
EmsisoftGen:Variant.Ransom.Cerber.311 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Dropper
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.252A604
MicrosoftRansom:Win32/Cerber.J
ArcabitTrojan.Ransom.Cerber.311
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cerber.311
Acronissuspicious
McAfeeGeneric.drb
MAXmalware (ai score=100)
VBA32suspected of Heur.Malware-Cryptor.Filecoder
MalwarebytesTrojan.Graftor
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.93 (RDML:XU2A3UwI5NPOFIErmCDe6g)
YandexTrojan.Zerber!BbOCFZhHgqA
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DNUG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HwoCEpsA

How to remove Trojan.Graftor?

Trojan.Graftor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment