Malware

Graftor.346507 malicious file

Malware Removal

The Graftor.346507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.346507 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Anomalous binary characteristics

How to determine Graftor.346507?


File Info:

crc32: E4C27519
md5: b662197f4522cd3d1603182d621c2a3d
name: B662197F4522CD3D1603182D621C2A3D.mlw
sha1: 0131b0491e5dedd383c8690e651d44daa16e31ca
sha256: a5226952f98ddd6e9dfb194cbacf0d1f2157b56260c730cbb2ad844afa7427a8
sha512: 5222de50d15c34e55bd08ac89c506f95cbc1fed343fa4d8a97d4fa41fc746c8d9add3d6679e9da3b84531534eb2d7735658d049309b2c256097447f02a9ae8ac
ssdeep: 12288:KIGcdNLwguLbt0vdN3BGDY+l/dxBuRJi6z5IpkfPiheuozx1:z1wgfNuNVei6z5IlhVo
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc
InternalName: Apple@Inc
FileVersion: 3.0.0.2
CompanyName: Apple@Inc
LegalTrademarks:
Comments:
ProductName: Apple@Inc
ProductVersion: 2.0.0.1
FileDescription: Windows Application
OriginalFilename:
Translation: 0x0416 0x04e4

Graftor.346507 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.50694
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Fsysna.18181
ALYacGen:Variant.Graftor.346507
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.34b4838c
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.f4522c
SymantecInfostealer.Bancos
ESET-NOD32a variant of Win32/Spy.Banker.ACBX
APEXMalicious
AvastWin32:Banker-LWR [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.kjpp
BitDefenderGen:Variant.Graftor.346507
NANO-AntivirusTrojan.Win32.Banker.euqqeo
MicroWorld-eScanGen:Variant.Graftor.346507
TencentWin32.Trojan.Blocker.Peza
Ad-AwareGen:Variant.Graftor.346507
SophosMal/Generic-S
ComodoMalware@#1ovqqs8i72gxc
BitDefenderThetaGen:NN.ZelphiF.34608.RG0@aSBLsanG
VIPREBehavesLike.Win32.Malware.eah (mx-v)
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.b662197f4522cd3d
EmsisoftGen:Variant.Graftor.346507 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1128283
MicrosoftTrojan:Win32/Tnega!ml
AegisLabTrojan.Win32.Blocker.4!c
GDataGen:Variant.Graftor.346507
AhnLab-V3Trojan/Win32.Blocker.C1803266
McAfeeArtemis!B662197F4522
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!AJ58UdLKpSE
IkarusTrojan-Spy.Agent
FortinetW32/Spy.BANKER.ACBX!tr
AVGWin32:Banker-LWR [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOsA

How to remove Graftor.346507?

Graftor.346507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment