Malware

Graftor.140361 removal

Malware Removal

The Graftor.140361 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.140361 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.140361?


File Info:

name: 6ADDFDEBE4D2AC571647.mlw
path: /opt/CAPEv2/storage/binaries/7d4a53f00b70a9b083d30ef4616b84f3c5db3d14c817e882aa141c55898eb3c1
crc32: 3E280FA3
md5: 6addfdebe4d2ac5716478a171c02c1e1
sha1: 0d83a4f89f2e568a91294ba7c18aa1fa979a203d
sha256: 7d4a53f00b70a9b083d30ef4616b84f3c5db3d14c817e882aa141c55898eb3c1
sha512: 76613b03423dd92030d00598781ef5669bfaa159fb5270eb71773a7a023083433f76671b992a9dfca6da41665f27b4caf736ef8a0cae7612a4ccd3d4256bce97
ssdeep: 3072:b7axojr7FuFAKmEciZGVH7ZpWsmcb4AGgayamsrzk:QmdSClfhKrzk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136D3AE20F608D036F059F6F23518D299A5393D311A98AD437AC17F252A722E39DF875B
sha3_384: 8cdf81558adcf5a108c7eea477bb2f1f8116f788c1293180ac0a9ff46ea5181a73aba53f086ecb61f60ba09814602442
ep_bytes: 68d8194000e8f0ffffff000000000000
timestamp: 2014-08-15 18:05:16

Version Info:

Translation: 0x0409 0x04b0
LegalTrademarks: uvbwrn
ProductName: nmoikjz
FileVersion: 9.07
ProductVersion: 9.07
InternalName: rmuvqo
OriginalFilename: rmuvqo.exe

Graftor.140361 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lfq7
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.140361
FireEyeGeneric.mg.6addfdebe4d2ac57
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cc
McAfeeW32/Worm-AAEH.s!6ADDFDEBE4D2
VIPREGen:Variant.Graftor.140361
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Variant.Graftor.140361
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.89f2e5
BaiduWin32.Worm.Autorun.l
SymantecW32.Changeup!gen46
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AYZC
APEXMalicious
ClamAVWin.Worm.Vobfus-7194261-0
KasperskyTrojan.Win32.Agent.agcsv
AlibabaWorm:Win32/Injector.47c08473
NANO-AntivirusTrojan.Win32.Agent.dyeply
RisingWorm.Vobfus!8.10E (TFE:3:BKAHhiwavhI)
SophosMal/VB-ALW
F-SecureWorm.WORM/Vobfus.A.603
DrWebWin32.HLLW.Autoruner2.12869
ZillyaTrojan.Agent.Win32.460070
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.140361 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GoogleDetected
AviraWORM/Vobfus.A.603
VaristW32/Vobfus.OM.gen!Eldorado
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus
XcitiumWorm.Win32.VB.NG@4xgp5b
ArcabitTrojan.Graftor.D22449
ZoneAlarmTrojan.Win32.Agent.agcsv
GDataGen:Variant.Graftor.140361
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R110258
BitDefenderThetaAI:Packer.C9769F8620
ALYacGen:Variant.Graftor.140361
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan.Agent.Aujl
YandexTrojan.Agent!OhfNm8cxBpE
IkarusTrojan-Downloader.Win32.Beebone
MaxSecureTrojan.Malware.7044902.susgen
FortinetW32/VB.ALW!tr
AVGWin32:VB-AIGQ [Trj]
AvastWin32:VB-AIGQ [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.140361?

Graftor.140361 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment