Malware

Graftor.116379 (file analysis)

Malware Removal

The Graftor.116379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.116379 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Graftor.116379?


File Info:

name: 0A8C53DFCD4ED62EFE4F.mlw
path: /opt/CAPEv2/storage/binaries/5de082c5d8f5ce9ae96167abe3670f4325347dd7da4ba399dbf98a6819032d18
crc32: A01E37EA
md5: 0a8c53dfcd4ed62efe4f7e4374655fd9
sha1: a98ab24e8d68b657afaee8404e14b70f6bb6d93c
sha256: 5de082c5d8f5ce9ae96167abe3670f4325347dd7da4ba399dbf98a6819032d18
sha512: 553ca4b3f06fc1190b4468e8d836d00b6a9a42ebc61723157c3e772ddf4dd5062f91044b4b36acd98b8ed483d4b526b70ca0a647606bddd553cb4195136d2474
ssdeep: 1536:3XQOzQk5hzo4l+G2dDMWrkibIfEKanAHXDVtedR2TDiej:3X5z95h04s4Wgi0ZVttTOej
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D88349496E43D453E9048DB0C39681F14BFCAC53F98266BFEB80FE0E34B210959969BD
sha3_384: 444f1f4c0cac9ed42bb0b09e1e1306d9485f0c8f150d6dde0f3a367f34846de3b1420e8a8203efe6bb492181b5bb3540
ep_bytes: 558bec6aff68a8494000687435400064
timestamp: 2013-09-26 13:12:52

Version Info:

0: [No Data]

Graftor.116379 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.116379
ClamAVWin.Trojan.Zbot-9793403-0
FireEyeGeneric.mg.0a8c53dfcd4ed62e
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Graftor.116379
CylanceUnsafe
VIPREGen:Variant.Graftor.116379
Sangfor[ARMADILLO V1.71]
K7AntiVirusRiskware ( 0040eff71 )
AlibabaVirTool:Win32/CeeInject.66fe8fab
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fcd4ed
VirITTrojan.Win32.Generic.AO
CyrenW32/Trojan.NTYN-8905
SymantecTrojan.Zbot!gen58
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ANLW
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.116379
NANO-AntivirusTrojan.Win32.Tepfer.cqmxzt
AvastWin32:Fareit-JX [Trj]
TencentMalware.Win32.Gencirc.10c7a1ab
Ad-AwareGen:Variant.Graftor.116379
EmsisoftGen:Variant.Graftor.116379 (B)
ComodoTrojWare.Win32.Spy.Zbot.D@52grij
DrWebTrojan.PWS.Stealer.3243
ZillyaTrojan.Zbot.Win32.139134
TrendMicroTROJ_GEN.R002C0CHI22
McAfee-GW-EditionPWSZbot-FEN!0A8C53DFCD4E
SophosML/PE-A + Mal/EncPk-ALR
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.116379
JiangminTrojan/Blocker.grs
AviraTR/Spy.Zbot.8827785
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Zbot.qc.(kcloud)
ArcabitTrojan.Graftor.D1C69B
MicrosoftVirTool:Win32/CeeInject.gen!KK
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R83735
Acronissuspicious
McAfeePWSZbot-FEN!0A8C53DFCD4E
MAXmalware (ai score=100)
VBA32Hoax.Blocker
TrendMicro-HouseCallTROJ_GEN.R002C0CHI22
RisingMalware.Undefined!8.C (TFE:5:pL20zIGBg4B)
YandexTrojan.GenAsa!4mJIYnjA1gs
IkarusTrojan-Downloader.Win32.Dimegup
FortinetW32/SpyZbot.PVJV!tr
BitDefenderThetaGen:NN.ZexaF.34606.fqZ@aSVM4Nri
AVGWin32:Fareit-JX [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.116379?

Graftor.116379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment