Malware

Graftor.213466 (file analysis)

Malware Removal

The Graftor.213466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.213466 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.213466?


File Info:

crc32: F13EEF1D
md5: 43d27a270ce14c1c66b363046a59dc30
name: 43D27A270CE14C1C66B363046A59DC30.mlw
sha1: bf9a50878798e3b066b2408eb47514aaae4531fe
sha256: 6018e086cf3b8c5aad5f4c5c3c3be7dcc20702f42817ba18f73de289567e2ccd
sha512: f3faaed1919e89e05fcc8923bfffd15cdf4871e1c67197ef94e0b3947ceee1124a38fc92d3a96f1d8781103aa3e2f90dbc4020fd5ace36d568a08e297bdee981
ssdeep: 768:ucG3o3WOXVhUJxjENcfzVzw7kITfWgp7h9KEUmxtZG07MGDi/3LglfhG2komBWF:ucnhUjEGZ87kgHztZGtGO3uZZ4BAT/x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
LegalCopyright: Google Inc. Copyright xa9 2017
InternalName: 1
FileVersion: 0.00.0001
CompanyName: Google Inc.
LegalTrademarks: Google Inc.
ProductName: Google Inc.
ProductVersion: 0.00.0001
FileDescription: Google Inc.
OriginalFilename: 1.dll

Graftor.213466 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056faf61 )
LionicTrojan.Win32.Agent.4!c
DrWebBackDoor.Bladabindi.13678
ClamAVWin.Trojan.Generic-7587573-0
ALYacGen:Variant.Graftor.213466
CylanceUnsafe
ZillyaTrojan.Agent.Win32.856818
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056faf61 )
Cybereasonmalicious.70ce14
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CHBF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Agent.qwespl
BitDefenderGen:Variant.Graftor.213466
NANO-AntivirusTrojan.Win32.Graftor.eumffj
MicroWorld-eScanGen:Variant.Graftor.213466
TencentWin32.Trojan.Agent.Pdwc
Ad-AwareGen:Variant.Graftor.213466
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34236.km0@aKcLdqaG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXDE-ND!43D27A270CE1
FireEyeGeneric.mg.43d27a270ce14c1c
EmsisoftGen:Variant.Graftor.213466 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.dnlq
AviraHEUR/AGEN.1116391
Antiy-AVLTrojan/Generic.ASMalwS.2264645
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Graftor.213466
AhnLab-V3Trojan/Win32.Agent.R217631
McAfeeGenericRXDE-ND!43D27A270CE1
MAXmalware (ai score=99)
VBA32Trojan.Agent
PandaTrj/GdSda.A
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!WUY7hNTuC7o
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CHBF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.213466?

Graftor.213466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment