Malware

Graftor.351091 malicious file

Malware Removal

The Graftor.351091 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.351091 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.351091?


File Info:

name: DCEF244337D149CE80B3.mlw
path: /opt/CAPEv2/storage/binaries/2596dc3a4b8c2bd14bf24a238fe5b1a44ef0fa05f3f31a9763e3d08c0bfa0ba1
crc32: D6C8EF43
md5: dcef244337d149ce80b350f9af381c8a
sha1: 7df5f53e85b4093aeb9affd7db1df80e1fd9dc2f
sha256: 2596dc3a4b8c2bd14bf24a238fe5b1a44ef0fa05f3f31a9763e3d08c0bfa0ba1
sha512: 2b2bf087c75c423c48c6ce691f0354317239b19fce824c9f2f11f3fcc5592d08de57ca78b0fd25a12e8e228221367d051abc5e47ffe1a5bdddc0caeaffd63cf9
ssdeep: 6144:YfKROO3/T0P8YiAdDou+EOH9ZMJiOErB+cBIM05iOy+3j1:OKHY0YbEu+EwLXBILD1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116844B75F640D237E4225CB89C1EE3E95479B6302E385C57FAE06F4C58B51C3AA2B683
sha3_384: 3969a1b7827460b23235e41db2973ec4601bb6040c62af8e9330b4e6645bf238dc52a2f6b07acf04e019d8bac4a77bb7
ep_bytes: 558bec83c4f4b8a4f6e402e8a86ffbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.351091 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Graftor.351091
FireEyeGeneric.mg.dcef244337d149ce
SkyhighBehavesLike.Win32.Sytro.fh
ALYacGen:Variant.Graftor.351091
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Graftor.351091
SangforWorm.Win32.Save.a
Cybereasonmalicious.e85b40
ArcabitTrojan.Graftor.D55B73
BitDefenderThetaGen:NN.ZelphiF.36792.xyW@aqlmQJp
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kovter.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Yakes.pef
BitDefenderGen:Variant.Graftor.351091
AvastSf:ShellCode-AO [Trj]
TencentTrojan.Win32.Kovter.16000580
EmsisoftGen:Variant.Graftor.351091 (B)
F-SecureDropper.DR/Delphi.Gen
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.emcqq
GoogleDetected
AviraDR/Delphi.Gen
MAXmalware (ai score=80)
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kovter.R@8f5pqh
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Yakes.pef
GDataGen:Variant.Graftor.351091
VaristW32/Kovter.AM.gen!Eldorado
AhnLab-V3Malware/Win32.Generic.C4030823
McAfeeGenericRXUD-VQ!DCEF244337D1
Cylanceunsafe
RisingTrojan.Kovter!1.A7CF (CLASSIC)
IkarusTrojan.Patched3
FortinetW32/Kovter.C!tr
AVGSf:ShellCode-AO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Graftor.351091?

Graftor.351091 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment