Malware

Graftor.103164 removal guide

Malware Removal

The Graftor.103164 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.103164 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Graftor.103164?


File Info:

name: 8E5EDCEFA18AE5FFBA82.mlw
path: /opt/CAPEv2/storage/binaries/acb46ea395159d60ce9f96a0d9f981b7596c5204cc737cd2b7f31b1f7ff33365
crc32: E37F642E
md5: 8e5edcefa18ae5ffba8230e0a5346490
sha1: b3bf4e10f3b51db9a247a8ec1f18176721cc6ef4
sha256: acb46ea395159d60ce9f96a0d9f981b7596c5204cc737cd2b7f31b1f7ff33365
sha512: b3f41192b0410332f16a60f732b63566c8d753ca000949b387c005cc652578a2d9e2251e3877930e04d60cb47e5280ff0469216f85bc7aa66d7b282c3520bf35
ssdeep: 6144:DZWMfwaaMrMM2gGEghjdQLYpfuHB/e5QaLrN36pgVZv2JL3r7ba:DJ0MAMIjdQUpfo/e5Q23sLX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1841269A6B39431DCD156363DE6B680036E7D0036E461A37BF452FE1E71E85363E22C
sha3_384: 72cc65450928e997d5e8e321b4694988d548f4768a3d73cde61772a94b5dc3c906e94280ed65a75265ea404764ece3b4
ep_bytes: e8fa160000e978feffff8bff558bec81
timestamp: 2013-05-31 08:03:11

Version Info:

Comments: lpk.dll/usp10.dll专杀工具-nod32专版
CompanyName: NOD32激活码之家
FileDescription: lpk.dll/usp10.dll专杀工具-nod32专版
FileVersion: 1.0
InternalName: Kill-lpk.dll-usp10.dll.exe
LegalCopyright: NOD32激活码之家
OriginalFilename: Kill-lpk.dll-usp10.dll.exe
ProductName: lpk.dll/usp10.dll专杀工具-nod32专版
ProductVersion: 1, 0, 0, 0

Graftor.103164 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Graftor.103164
ClamAVWin.Trojan.9242256-2
FireEyeGeneric.mg.8e5edcefa18ae5ff
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FCUG!8E5EDCEFA18A
Cylanceunsafe
ZillyaWorm.Luder.Win32.747
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Agent.t
VirITTrojan.Win32.SHeur4.BKDV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlowSpirit.G potentially unsafe
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Havex.xt
BitDefenderGen:Variant.Graftor.103164
NANO-AntivirusTrojan.Win32.FlowSpirit.gdjsls
AvastWin32:WormX-gen [Wrm]
TencentTrojan.Win32.Click.a
TACHYONTrojan/W32.Havex.402944
EmsisoftGen:Variant.Graftor.103164 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.DownLoader9.32433
VIPREGen:Variant.Graftor.103164
TrendMicroTROJ_NOUPACK.SM
SophosGeneric ML PUA (PUA)
IkarusVirus.Win32.PePatch
GDataGen:Variant.Graftor.103164
JiangminTrojan/Generic.bjaby
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Win32.Unknown
Kingsoftmalware.kb.a.1000
XcitiumMalware@#2wvzmeiygwo08
ArcabitTrojan.Graftor.D192FC
ZoneAlarmTrojan.Win32.Havex.xt
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Downloader.HE.gen!Eldorado
AhnLab-V3Worm/Win32.Luder.R74115
VBA32BScope.Trojan.Download
ALYacGen:Variant.Graftor.103164
MAXmalware (ai score=100)
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NOUPACK.SM
RisingTrojan.Generic@AI.100 (RDML:4J7v/IBZ0ccYWCXFdQ9nCg)
YandexTrojan.GenAsa!q4wJd9NMA8Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FlowSpirit.A!tr
BitDefenderThetaGen:NN.ZexaF.36744.yu0@a0@yu3ij
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.0f3b51
DeepInstinctMALICIOUS

How to remove Graftor.103164?

Graftor.103164 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment