Malware

Should I remove “Graftor.110643”?

Malware Removal

The Graftor.110643 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.110643 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Graftor.110643?


File Info:

name: 38B0C9241AA90BE4F72E.mlw
path: /opt/CAPEv2/storage/binaries/56e302132ac9bf2969e5237c1d362ac78cc8b6cd35116fb9cbd7ccb46447591b
crc32: 97051D70
md5: 38b0c9241aa90be4f72ee5ba080b7a2c
sha1: 7ab85274f7040e54721a5109f8ff849787c93c28
sha256: 56e302132ac9bf2969e5237c1d362ac78cc8b6cd35116fb9cbd7ccb46447591b
sha512: 78548cb2e7ad947f78ea4ba964b9938c7b7f4ee06840258f2bc8a908faab99d58b7a84a0559d957b1acc6ce1c9e29efa19846299679020116d9a41500f9d0bd8
ssdeep: 384:ikJRxYTyjazqXhzjJcyZ9tIXhuyYYswJ5XWd2IINRo86MzR:iiRxYTfwt6yZ9teuyTswJhIINRo8T1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9A2BF4B4FA60F22DD745DB50A47874C6F7BA02E5339A3882FBD4EDB2E6A01445A834D
sha3_384: 1eaa6df5a7a5a3786a5ec58f3b44ba005b919eeeed603945b3a8003c70ad159aeb91ae1819d897514a18ed0db7920abc
ep_bytes: 558bec51a1c430400053565733ff3bc7
timestamp: 2012-12-10 06:45:28

Version Info:

0: [No Data]

Graftor.110643 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.110643
FireEyeGeneric.mg.38b0c9241aa90be4
ALYacGen:Variant.Graftor.110643
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Graftor.D1B033
BitDefenderThetaGen:NN.ZexaF.34212.biY@amy1hJp
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
KasperskyUDS:Backdoor.MSIL.Bladabindi.bsqz
BitDefenderGen:Variant.Graftor.110643
AvastFileRepMalware
Ad-AwareGen:Variant.Graftor.110643
EmsisoftGen:Variant.Graftor.110643 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.arkud
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASMalwS.27B7E3
MicrosoftBackdoor:MSIL/Bladabindi.AL
GDataGen:Variant.Graftor.110643
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic.rp
MAXmalware (ai score=87)
VBA32Trojan.MSIL.Disfa
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazrmq+Fe3kp3qfdqPgLBcuCM)
IkarusVirus.Win32.Heur
AVGFileRepMalware

How to remove Graftor.110643?

Graftor.110643 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment