Malware

Should I remove “Graftor.1148”?

Malware Removal

The Graftor.1148 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.1148 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Graftor.1148?


File Info:

name: 23636F7895D902480F48.mlw
path: /opt/CAPEv2/storage/binaries/2ce1ee3125ca3e31805d9681e865094cf1447e5d123d9696c61c658363a7a3c9
crc32: BF7C0477
md5: 23636f7895d902480f481cb2de93e706
sha1: 9feafca04f803f9eb2e59131938a5a35ec568942
sha256: 2ce1ee3125ca3e31805d9681e865094cf1447e5d123d9696c61c658363a7a3c9
sha512: 9a5e4ea8fe6bdec3af824a7dfafa08c553b032c81837a43fb376fb76d6fc9115bd4cfd5dcfff3127b79780591effa72cf7d3901bc8fe29a5391cd2dd0f700947
ssdeep: 12288:JmzKjYo46VX3Ybn11PqILyxfrV7iqVgm2PB9AhUiGWHYyFfFpBW8wxd08KEeOu0x:JmzK8odp3Yb11MUHcgBHKHO7x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139160AB976CDF1ABAC436DA29DBFC289C1D0FC36130F5916A514AD61C00C9A4EED3A47
sha3_384: ebf9e423870af765c3f35f6d7ba61ccc09b52ee9c1402bcf2ea3c5b5f94f8de30407a64cb17bdeb0e690367985483978
ep_bytes: 6864234000e8eeffffff000000000000
timestamp: 2011-03-25 01:39:32

Version Info:

Translation: 0x0409 0x04b0
Comments: DEBMCIULN
CompanyName: FGYUPQKJB
FileDescription: NXCMDEQVW
ProductName: GEHLVOUJL
FileVersion: 19.08.0025
ProductVersion: 19.08.0025
InternalName: dzcpbju
OriginalFilename: dzcpbju.exe

Graftor.1148 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.ArchSMS.3!c
MicroWorld-eScanGen:Variant.Graftor.1148
FireEyeGeneric.mg.23636f7895d90248
McAfeeArtemis!23636F7895D9
ZillyaTrojan.ArchSMS.Win32.31067
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0055e3991 )
AlibabaRiskWare:Win32/ArchSMS.1f765110
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.895d90
BitDefenderThetaAI:Packer.E5F2031D21
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.FLW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHoax.Win32.ArchSMS.hjjb
BitDefenderGen:Variant.Graftor.1148
NANO-AntivirusRiskware.Win32.ArchSMS.ecjvad
AvastWin32:VB-SLO [Trj]
TencentMalware.Win32.Gencirc.114f7597
EmsisoftGen:Variant.Graftor.1148 (B)
F-SecureTrojan.TR/Dropper.Gen2
DrWebTrojan.DownLoader21.41315
VIPREGen:Variant.Graftor.1148
McAfee-GW-EditionBehavesLike.Win32.Trojan.wm
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-C
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Graftor.1148
JiangminHoax.ArchSMS.brcy
AviraTR/Dropper.Gen2
Antiy-AVLHackTool[Hoax]/Win32.ArchSMS
XcitiumMalware@#11m7dk1tcnkvf
ArcabitTrojan.Graftor.D47C
ViRobotTrojan.Win32.GandCrab.Gen.A
ZoneAlarmHoax.Win32.ArchSMS.hjjb
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32BScope.Trojan-Spy.Zbot
ALYacGen:Variant.Graftor.1148
MAXmalware (ai score=99)
Cylanceunsafe
PandaGeneric Malware
RisingMalware.Undefined!8.C (TFE:4:VYTn4MM3zOF)
YandexTrojan.GenAsa!/6KdO7ofnYw
IkarusTrojan-Dropper.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.345267!tr
AVGWin32:VB-SLO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.1148?

Graftor.1148 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment