Malware

Graftor.118587 (file analysis)

Malware Removal

The Graftor.118587 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.118587 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Graftor.118587?


File Info:

crc32: 813CBAF4
md5: 6d9a1dfa56a2200f733074bce2a58076
name: 6D9A1DFA56A2200F733074BCE2A58076.mlw
sha1: 5becaea71a575c8dae2ef2e7dabfb9a9c2067df4
sha256: a22ce0d1a6b213e8f0396af9b179ae8271fd394be562d63c841470fd11c2605f
sha512: 0ff9e8020d77e6dd424e893155a25c55f6f42d208ee7444342848c2551cc1b7e34b60973d73d26226dc23394d9004f07a4098bfc0fddf326f3508d34d4b82d7e
ssdeep: 1536:o1SVhfepuxmn8vMD6f5ppqWpynTk4nwKUF:oQouxmwMm5zqWO/wKUF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x8bf7x572824x5c0fx65f6x5185x5220x9664x672cx8f6fx4ef6,x4efbx4f55x8fddx53cdx6cd5x5f8bx6cd5x89c4x7684x4e8bx4e0ex4f5cx8005x65e0x5173
FileVersion: 1.0.0.0
CompanyName: D
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: Login
ProductVersion: 1.0.0.0
FileDescription: CrossFireHK
Translation: 0x0804 0x04b0

Graftor.118587 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005257651 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Graftor.118587
CylanceUnsafe
ZillyaVirus.Hupigon.Win32.5
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Graftor.118587
K7GWTrojan ( 005257651 )
Cybereasonmalicious.a56a22
CyrenW32/Downloader.AT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/BlackMoon.af7365f1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Graftor.118587
TencentWin32.Trojan.Spy.Wsas
Ad-AwareGen:Variant.Graftor.118587
SophosML/PE-A + Mal/Packer
BitDefenderThetaGen:NN.ZexaF.34628.emKdaGPNTAib
VIPREPacker.NSAnti.Gen (v)
TrendMicroMal_MLWR-24
McAfee-GW-EditionBehavesLike.Win32.Dropper.kc
FireEyeGeneric.mg.6d9a1dfa56a2200f
EmsisoftGen:Variant.Graftor.118587 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftPack.Win32.Gen.bot!ep-44128
GDataWin32.Application.PUPStudio.A
AhnLab-V3Malware/Win32.Generic.R372376
Acronissuspicious
McAfeeArtemis!6D9A1DFA56A2
MAXmalware (ai score=85)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallMal_MLWR-24
RisingTrojan.Injector!1.A1C3 (CLOUD)
IkarusPUA.BlackMoon
MaxSecureVirus.W32.Delf.AQ
FortinetRiskware/Mal_MLWR
Paloaltogeneric.ml

How to remove Graftor.118587?

Graftor.118587 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment