Malware

Graftor.116809 removal tips

Malware Removal

The Graftor.116809 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.116809 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Graftor.116809?


File Info:

name: 37648553F4EE6C5CB712.mlw
path: /opt/CAPEv2/storage/binaries/3c72d509f5ba2f6bde93c583835e3fa87875b90cdb3b864e01d215b1caec100e
crc32: 86B81709
md5: 37648553f4ee6c5cb712cca446340a9a
sha1: 3b704418aeeea80b94da3f008d57303242b350be
sha256: 3c72d509f5ba2f6bde93c583835e3fa87875b90cdb3b864e01d215b1caec100e
sha512: 95cea52e63ef2ea2a3822ae9d64f4477835c8d2f29a6ff2056ae3905dc9ae956a84b36c066d04f8c9956f5d2afa924b5baabae444a25d7484dc7e0afe5cfee85
ssdeep: 384:Xt4NXw3X0b/E8Q+gWNLOWwX4kk94Rgfm7jY/9u1T:db3X6/bg4CWwX4kkyam/Y1o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB923A50DE55A983CA53C3F0F4AE26BAC4B718B85E5F42867380CB9314756E352E9E0F
sha3_384: 11fefa2022c65e057f1743e97243941341d9c5768a0b823b598971bad89516672a2660ccd33bd06e75bf334824c85318
ep_bytes: 558bec6aff68e0604000682051400064
timestamp: 2012-11-20 00:10:14

Version Info:

0: [No Data]

Graftor.116809 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Agent.2!c
MicroWorld-eScanGen:Variant.Graftor.116809
FireEyeGeneric.mg.37648553f4ee6c5c
ALYacGen:Variant.Graftor.116809
CylanceUnsafe
VIPREGen:Variant.Graftor.116809
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 0055e4041 )
AlibabaTrojan:Win32/Ixeshe.68eadc38
K7GWTrojan ( 0055e4041 )
Cybereasonmalicious.3f4ee6
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.TGM
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ixeshe.aa
BitDefenderGen:Variant.Graftor.116809
NANO-AntivirusTrojan.Win32.Agent.bdlshi
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.uzk
Ad-AwareGen:Variant.Graftor.116809
EmsisoftGen:Variant.Graftor.116809 (B)
ComodoMalware@#18gi35x79lfic
DrWebTrojan.DownLoader8.27995
McAfee-GW-EditionBackDoor-EKF!37648553F4EE
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.116809
AviraHEUR/AGEN.1246230
Antiy-AVLTrojan/Generic.ASMalwS.325E
ArcabitTrojan.Graftor.D1C849
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
Acronissuspicious
McAfeeBackDoor-EKF!37648553F4EE
MAXmalware (ai score=99)
VBA32BScope.Adware.Agent
MalwarebytesMachineLearning/Anomalous.97%
RisingTrojan.Generic@AI.98 (RDML:21ACifm87u7F30o2cVVJ5g)
YandexTrojan.Rogue!AJvSfmS6SEE
IkarusTrojan.Win32.Swisyn
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34786.bqW@aC7RfEc
AVGWin32:Malware-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.116809?

Graftor.116809 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment