Malware

Should I remove “Graftor.27220”?

Malware Removal

The Graftor.27220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.27220 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Graftor.27220?


File Info:

name: CB34EA886D50FC4E6C5B.mlw
path: /opt/CAPEv2/storage/binaries/63a9188deb07238326b5e37c44b4da8ff5f50f14b234acfedf64a3f4134c1279
crc32: 224C0AC2
md5: cb34ea886d50fc4e6c5b07f6677df3f0
sha1: 0babcab9f4c3b3064602d7781c6396caf08d6207
sha256: 63a9188deb07238326b5e37c44b4da8ff5f50f14b234acfedf64a3f4134c1279
sha512: 5ebf00d396b383bbdd79f231201e692397d2050b9088a1bce0cf66b764748cb06df71b34f32ec1336790bdd6980e9a7fb0bb07da8c09203f79fa44c73ddc54f6
ssdeep: 384:5Z0tT0GKFeDyoTjCDZud61Fxbn7amk7PWRI6RwxFwLD0YvphlW:IZDKFeFL8bD7amkT3Aph
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E131ACBEE618848C1DA02328AAF857F11677D96467146CF3CCCFABBB5F8940D619291
sha3_384: 1c69739b29e100dc8bf0df58a7fe1f9e54d6027473262cdb353d81ed8e1a8f4a6319545f5f9c16bed85aa380166a0894
ep_bytes: 558bec6aff68c81a400068902a400064
timestamp: 2012-01-21 02:17:08

Version Info:

Comments: http://www.metaquotes.net
CompanyName: MetaQuotes Software Corp.
FileDescription: MetaTrader
FileVersion: 4.0.0.409
InternalName: MetaTrader
LegalCopyright: ? 2001-2011, MetaQuotes Software Corp.
LegalTrademarks: MetaTrader?
OriginalFilename:
PrivateBuild:
ProductName: MetaTrader
ProductVersion: 4.0.0.409
SpecialBuild:
Translation: 0x0804 0x04b0

Graftor.27220 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Graftor.27220
McAfeeGenericRXCS-WJ!CB34EA886D50
CylanceUnsafe
VIPREGen:Variant.Graftor.27220
SangforSuspicious.Win32.Save.ins
AlibabaTrojan:Win32/Farfli.98e7604f
Cybereasonmalicious.86d50f
CyrenW32/Zegost.AA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PFE
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.27220
NANO-AntivirusTrojan.Win32.Agent.oyewg
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Agen.Pgil
Ad-AwareGen:Variant.Graftor.27220
EmsisoftGen:Variant.Graftor.27220 (B)
ComodoBackdoor.Win32.Agent.FLG@4of3sq
ZillyaTrojan.Farfli.Win32.37237
McAfee-GW-EditionBehavesLike.Win32.Virut.pm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.cb34ea886d50fc4e
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.27220
JiangminHeur:Backdoor/PcClient
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1225338
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Graftor.D6A54
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Gen
VBA32BScope.Trojan.SvcHorse.01643
ALYacGen:Variant.Graftor.27220
RisingTrojan.Dynamer!8.3A0 (TFE:5:dNOku2nEaxJ)
YandexTrojan.GenAsa!nEnSD/sjv3s
IkarusTrojan-Dropper.Win32.Zegost
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Torr.BH!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34682.ci0@aWCp0Qhb
AVGFileRepMalware [Misc]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.27220?

Graftor.27220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment