Malware

Graftor.32525 removal tips

Malware Removal

The Graftor.32525 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.32525 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.32525?


File Info:

name: F42470AE7B8A2A39CC74.mlw
path: /opt/CAPEv2/storage/binaries/7e607faa30e92930daaa25f8c9a2f42bde57061cbab9479be00a4963ad41f43e
crc32: CC07FB16
md5: f42470ae7b8a2a39cc74c925a61a321e
sha1: 06bd7911a88a136e9639a48079478ee5991c1ee9
sha256: 7e607faa30e92930daaa25f8c9a2f42bde57061cbab9479be00a4963ad41f43e
sha512: f45c53a89e4d12d902dc8044eab339eb2de41d54ad8dd15fb0c8924faac2aee31caa1e6e7357e536d340b9aeee20236f4a188db3962ead261e18d2aec47c2517
ssdeep: 3072:dyzJJTklav8i4zQsZlTNO6wsBspyZ8RrwD4jRWSR:gD4hZxsQBspqE1WSR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6B312098FE083B8C59894B3A784D9707DBF985BB6004F5B17A9CB2E2D0D7188DAC576
sha3_384: 7236ee13fbc675016341e8250d20038842a0eb8a3981242e70bc7729d07b4bff13c6aab2dcbe01352006fd79ed6f197f
ep_bytes: 53575655e8000000005d81ed07130010
timestamp: 2009-03-10 03:42:15

Version Info:

0: [No Data]

Graftor.32525 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Graftor.32525
ALYacGen:Variant.Graftor.32525
CylanceUnsafe
Sangfor[ASPACK V2.12]
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e7b8a2
VirITTrojan.Win32.Generic.AFHH
CyrenW32/SuspPack.DO.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32Win32/RiskWare.PEMalform.B
APEXMalicious
ClamAVWin.Downloader.85867-1
KasperskyTrojan-Dropper.Win32.Agent.khqe
BitDefenderGen:Variant.Graftor.32525
NANO-AntivirusTrojan.Win32.Libie.bockss
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Graftor.32525
ComodoPacked.Win32.MPEC.Gen@2oey7k
DrWebTrojan.DownLoad2.43967
ZillyaDownloader.VB.Win32.14889
TrendMicroTROJ_VB.JTL
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f42470ae7b8a2a39
SophosML/PE-A + Mal/VB-Y
IkarusTrojan-PSW.OnlineGames
GDataGen:Variant.Graftor.32525
JiangminTrojan/Vundo.cml
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
ArcabitTrojan.Graftor.D7F0D
ViRobotTrojan.Win32.A.Downloader.546304.J
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Backdoor/Win32.CSon.R2580
Acronissuspicious
McAfeeArtemis!F42470AE7B8A
VBA32Backdoor.Hupigon
TrendMicro-HouseCallTROJ_VB.JTL
RisingPacker.Win32.Crypt.eg (CLASSIC)
YandexTrojan.DL.VB!PdtFlrDkLVo
SentinelOneStatic AI – Malicious PE
FortinetW32/Onlinegames.ASE!tr
BitDefenderThetaGen:NN.ZexaF.34742.giZ@aClC7rm
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Graftor.32525?

Graftor.32525 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment