Malware

Graftor.3194 malicious file

Malware Removal

The Graftor.3194 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.3194 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.3194?


File Info:

crc32: EB0AE27F
md5: fcbda965e4bb669ef5a7f4e33a5d0f68
name: FCBDA965E4BB669EF5A7F4E33A5D0F68.mlw
sha1: 123acab84ba6a9aefc75f3d3f1cf129fca3bbdf6
sha256: 38b1b7802b0fe3b47002dc3d6cf5e3c360433bee072e4653cac2bfa61906f293
sha512: 5dc0ce5a1c140c9c0658e1f894efeb0e4602c1bd6b17815498d1a76946b2307a701c43382ae93137c5b568bf4efd20f22ed2d711616898077ff46935ee753ffc
ssdeep: 1536:/wZZnAEjEIZvumULmj4wrraK5dZ4Ltta9Km/ec3DtAL6bmZ4bXSjrAE+fySPoqR:InnAQVG/LytaKItS/fiLKS+f5Aq7i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2007 Avira GmbH. All rights reserved.
InternalName: AntiVir/Win32
FileVersion: 7.6.0.59
CompanyName: Avira GmbH
PrivateBuild:
LegalTrademarks: AntiVirxae is a registered trademark of Avira GmbH, Germany
Comments:
ProductName:
SpecialBuild:
ProductVersion: 7.6.0.59
FileDescription: AntiVir Command Line Scanner for Windows
OriginalFilename:
Translation: 0x0000 0x04b0

Graftor.3194 also known as:

BkavW32.FamVT.ZardedT.Trojan
K7AntiVirusTrojan ( 005298a21 )
LionicTrojan.Win32.Generic.lDC0
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Tazebama.235
CynetMalicious (score: 100)
CAT-QuickHealW32.Virut.G
ALYacGen:Variant.Graftor.3194
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.104378
SangforTrojan.Win32.Save.a
AlibabaWorm:Win32/Ramnit.b972f251
K7GWTrojan ( 0045434d1 )
Cybereasonmalicious.5e4bb6
BaiduWin32.Worm.Autorun.f
CyrenW32/Ramnit.K.gen!Eldorado
SymantecPacked.Protexor!gen1
ESET-NOD32Win32/Ramnit.A
ZonerTrojan.Win32.Ramnit.31771
APEXMalicious
AvastWin32:Vitro [Inf]
ClamAVWin.Trojan.Ramnit-7847
KasperskyWorm.Win32.Autorun.icp
BitDefenderGen:Variant.Graftor.3194
NANO-AntivirusTrojan.Win32.DownLoad2.wtigj
MicroWorld-eScanGen:Variant.Graftor.3194
TencentWorm.Win32.AutoRun.aaa
Ad-AwareGen:Variant.Graftor.3194
SophosMal/Generic-R + Troj/Ramnit-AP
ComodoTrojWare.Win32.Kryptik.KLV@4neax2
BitDefenderThetaGen:NN.ZexaF.34688.tu3@aKZuY4mi
VIPREPacked.Win32.PWSZbot.gen.cy (v)
TrendMicroTSPY_ZBOT.SMHA
McAfee-GW-EditionPWS-Zbot.gen.aud
FireEyeGeneric.mg.fcbda965e4bb669e
EmsisoftGen:Variant.Graftor.3194 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.dkmt
AviraTR/Drop.Liks.A
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Ramnit
GridinsoftTrojan.Win32.Gen.se!i
ArcabitTrojan.Graftor.DC7A
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Rn]
ZoneAlarmWorm.Win32.Autorun.icp
GDataGen:Variant.Graftor.3194
AhnLab-V3Trojan/Win32.Zbot.R19508
Acronissuspicious
McAfeePWS-Zbot.gen.aud
MAXmalware (ai score=81)
VBA32Worm.Autorun
MalwarebytesNimnul.Virus.FileInfector.DDS
PandaGeneric Malware
TrendMicro-HouseCallTSPY_ZBOT.SMHA
RisingMalware.XPACK!1.64E1 (CLOUD)
YandexTrojan.GenAsa!cSews1jOxBU
IkarusVirus.Win32.Virtob
MaxSecureWorm.Autorun.icp
FortinetW32/Kryptik.KLV!tr
AVGWin32:Vitro [Inf]
Paloaltogeneric.ml

How to remove Graftor.3194?

Graftor.3194 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment