Malware

Graftor.128326 malicious file

Malware Removal

The Graftor.128326 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.128326 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

morphed.ru
amnsreiuojy.ru
a.deltaheavy.ru

How to determine Graftor.128326?


File Info:

crc32: FD35DFFC
md5: b97e8dfd4cb3efd527497ef6922ce812
name: B97E8DFD4CB3EFD527497EF6922CE812.mlw
sha1: 2770d37b08c04163f366718636db14949121722d
sha256: fcf94167452aafb17f2a1d73d67eae1acd241c8653da65d120a7b243e2f47bfa
sha512: 9c1ae842ab3a44b8fc2669aa4de909b6ab97f0af38801f0af5b65ebd993f1fb4bec7673ce86fd4290e83d674388e89ca686a32325a3c26bb920c998e9e9c6a1e
ssdeep: 3072:DnT6kyxl5AzSuEENoL5WGIxIbc0q2jijk1dLv9gdVn9ARgzGOGFV:D7yxlyzHNQWnd0qSoGdL1g61b
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright Misejkaxa9 2013
InternalName: Ragiza
FileVersion: 2, 1, 3, 2
CompanyName: Hause
PrivateBuild: Kizbow
LegalTrademarks: Giokaxa9
Comments: Gezera
ProductName: Bigalov
SpecialBuild: Makanz
ProductVersion: 5, 1, 8, 4
FileDescription: Mikega
OriginalFilename: Magez
Translation: 0x0409 0x04b0

Graftor.128326 also known as:

BkavW32.FamVT.GraftorQ.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.128326
FireEyeGeneric.mg.b97e8dfd4cb3efd5
CAT-QuickHealWorm.Gamarue.B
McAfeeGeneric.gl.gen.a
CylanceUnsafe
VIPRETrojan.Win32.Inject.ea (v)
AegisLabWorm.Win32.Bundpil.o!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 0043f6bc1 )
BitDefenderGen:Variant.Graftor.128326
K7GWTrojan-Downloader ( 0043f6bc1 )
Cybereasonmalicious.d4cb3e
BaiduWin32.Trojan-Downloader.Wauchos.n
CyrenW32/Gamarue.C.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Injector-BDN [Trj]
ClamAVWin.Worm.Gamarue-6804112-0
KasperskyWorm.Win32.Bundpil.aws
AlibabaWorm:Win32/Bundpil.32068871
NANO-AntivirusTrojan.Win32.Andromeda.csstqi
ViRobotTrojan.Win32.Agent.1689890[UPX]
RisingWorm.Gamarue!1.A224 (CLOUD)
Ad-AwareGen:Variant.Graftor.128326
TACHYONWorm/W32.Bundpil.10812416
SophosMal/Generic-R + Mal/Inject-EA
ComodoTrojWare.Win32.Kryptik.BBYD@4y3c16
F-SecureHeuristic.HEUR/AGEN.1130429
DrWebBackDoor.Andromeda.178
TrendMicroTROJ_GEN.R002C0CAJ21
McAfee-GW-EditionBehavesLike.Win32.Flyagent.cc
EmsisoftGen:Variant.Graftor.128326 (B)
JiangminTrojan.Generic.mqhi
AviraHEUR/AGEN.1130429
Antiy-AVLTrojan[Dropper]/Win32.Injector
MicrosoftWorm:Win32/Gamarue.I
ArcabitTrojan.Graftor.D1F546
SUPERAntiSpywareTrojan.Agent/Gen- Blocker
ZoneAlarmWorm.Win32.Bundpil.aws
GDataGen:Variant.Graftor.128326
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Agent.C199145
BitDefenderThetaGen:NN.ZexaF.34804.lmKfaSoWbqnO
ALYacGen:Variant.Graftor.128326
MAXmalware (ai score=100)
VBA32Backdoor.Androm
MalwarebytesAndromeda.Backdoor.Downloader.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDownloader.Wauchos.L
TrendMicro-HouseCallTROJ_GEN.R002C0CAJ21
TencentMalware.Win32.Gencirc.10b3df62
YandexTrojan.Graftor!GOcs3Y/rt+I
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.BBYD!tr
AVGWin32:Injector-BDN [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Worm.405

How to remove Graftor.128326?

Graftor.128326 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment