Malware

Graftor.167507 removal

Malware Removal

The Graftor.167507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.167507 virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.167507?


File Info:

name: 226A1F78DD8C52079721.mlw
path: /opt/CAPEv2/storage/binaries/9b77a8f53219d1c5f8edf7b871dda32ddf16e46d7b6ad127b15f1309071ae80c
crc32: 1A182023
md5: 226a1f78dd8c52079721f48196ed1c47
sha1: 5a093b4251a0c25804c2a93cb2b9649f60b938c4
sha256: 9b77a8f53219d1c5f8edf7b871dda32ddf16e46d7b6ad127b15f1309071ae80c
sha512: 050ba1a2c82476f1281578964ec1b8a561b7a5bb218fa8ced25bc37e47a7b6e6699b93f73147a6c32aa2cad2f58f2ccca68882a0d16de285c8321eb61c7cb507
ssdeep: 12288:9Lxl7AuSfZ65SZOI9jORGpr/46bUfMbVWCQhPpNhPBIZPf83qKoRR:blETfZ6YZd98sb40DszNhYPf83qKoR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18005C0173880859CDE7D95F6B21781B4739ADCBED648A60C7FC833974EE1EA50826B07
sha3_384: 3cdef1e477825ab8586875046965bf3cd5f51959bb272fe30573583fe09b1b118d5171cb4b50c34d1f74bbfb34891681
ep_bytes: 60be004050008dbe00d0efffc787e4a9
timestamp: 2014-12-17 20:52:32

Version Info:

0: [No Data]

Graftor.167507 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.ArchSMS.mfkD
DrWebTrojan.Bankfraud.2232
MicroWorld-eScanGen:Variant.Graftor.167507
ClamAVWin.Keylogger.Banbra-9936388-0
FireEyeGeneric.mg.226a1f78dd8c5207
CAT-QuickHealTrojanDownloader.Banload
ALYacGen:Variant.Graftor.167507
Cylanceunsafe
ZillyaTrojan.Agent.Win32.524174
SangforDownloader.Win32.Banload.V8q5
K7AntiVirusTrojan-Downloader ( 004b23781 )
AlibabaTrojanDownloader:Win32/Banload.9fb837f8
K7GWTrojan-Downloader ( 004b23781 )
Cybereasonmalicious.8dd8c5
BitDefenderThetaAI:Packer.7607130D17
SymantecInfostealer.Bancos
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.UWQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Agent.kpd
BitDefenderGen:Variant.Graftor.167507
NANO-AntivirusTrojan.Win32.Bankfraud.dkqcen
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13ea8da2
EmsisoftGen:Variant.Graftor.167507 (B)
F-SecureTrojan.TR/Dldr.Banload.pzcbu
VIPREGen:Variant.Graftor.167507
TrendMicroTROJ_GEN.R002C0DGN23
McAfee-GW-EditionGenericR-CUJ!805D9731D16C
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Graftor.167507
JiangminHoax.ArchSMS.aiib
AviraTR/Dldr.Banload.pzcbu
Antiy-AVLTrojan[Banker]/Win32.Agent
ArcabitTrojan.Graftor.D28E53
ViRobotTrojan.Win.Z.Graftor.795136
ZoneAlarmTrojan-Banker.Win32.Agent.kpd
MicrosoftTrojanDownloader:Win32/Banload
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C670535
McAfeeArtemis!226A1F78DD8C
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGN23
RisingDownloader.Banload!8.15B (TFE:5:RTKGbVOLVEC)
YandexTrojan.GenAsa!k1UnN4zeXn4
IkarusTrojan.Win32.QQWare
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.UWQ!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.167507?

Graftor.167507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment