Malware

Graftor.318157 (B) (file analysis)

Malware Removal

The Graftor.318157 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.318157 (B) virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Graftor.318157 (B)?


File Info:

crc32: 3979A217
md5: b3870ec6ba7f7b0ef2e51efa93d0181e
name: B3870EC6BA7F7B0EF2E51EFA93D0181E.mlw
sha1: 3d7d99565d73e9e9ed0fc173d9baa1ae089f68dc
sha256: 30f1b8835ad0f1373e736891d281de0d79a38d0275f3e5d35e34860f83348af0
sha512: 01f3ceb93cb48729aac347a0e582f008997dc054b99036ef455dafa799c1b2cfcdfc0d171b818bfff9b4115ca531efc0bf8a2e1724ee29048f46f876a5391afb
ssdeep: 6144:SuHVzR7BneLZO4qIuGJYWC1gM6Zb6+TCYjMtH1yGI4Oe/oPRYYayHiS:PHVb45u8Cv6o+eYjMN1LxOe0RO2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2010
InternalName: YYx8bf4x8bddx5916x6302
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: YYx8bf4x8bddx5916x6302 x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: YYx8bf4x8bddx5916x6302 Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: YYx8bf4x8bddx5916x6302.EXE
Translation: 0x0804 0x04b0

Graftor.318157 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ALYacGen:Variant.Graftor.318157
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.6ba7f7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKOG
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Antavmu.astt
BitDefenderGen:Variant.Graftor.318157
MicroWorld-eScanGen:Variant.Graftor.318157
Ad-AwareGen:Variant.Graftor.318157
SophosTroj/Kryptik-XM
BitDefenderThetaGen:NN.ZexaF.34692.Gq3@a8EqbUgj
McAfee-GW-EditionBehavesLike.Win32.Emotet.hc
FireEyeGeneric.mg.b3870ec6ba7f7b0e
EmsisoftGen:Variant.Graftor.318157 (B)
eGambitUnsafe.AI_Score_87%
MicrosoftTrojan:Win32/Farfli.GKM!MTB
GDataWin32.Trojan.PSE.1SYPIY7
AhnLab-V3Trojan/Win.Agent.R417294
McAfeeArtemis!B3870EC6BA7F
MAXmalware (ai score=88)
VBA32BScope.Trojan.Tnega
MalwarebytesMalware.AI.2245317090
RisingTrojan.Kryptik!1.D571 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HKOG!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Graftor.318157 (B)?

Graftor.318157 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment