Malware

Graftor.35312 removal tips

Malware Removal

The Graftor.35312 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.35312 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Graftor.35312?


File Info:

name: EEA1F3BDA7880BC9755E.mlw
path: /opt/CAPEv2/storage/binaries/3cb79f2d4b0ad545ee5be8b07f2273a5a0251236f202cc4f7d0c632ead7a9bdd
crc32: CEA2EA66
md5: eea1f3bda7880bc9755e1cbba3d3805b
sha1: 0b7cf004e3856717ac4998e21bcb778b7380be8c
sha256: 3cb79f2d4b0ad545ee5be8b07f2273a5a0251236f202cc4f7d0c632ead7a9bdd
sha512: 2d3b876216b2d8a66a40d19163ecc198d0665db2c5f834dcb78c484144b994d7a97c3328195a6c15095ee71521ba986b894491c1b9694a466f34f39161f99c13
ssdeep: 3072:6qYsp0+t0hn+Otjrh+si2YW/wPObRWkCiYimyvop05:es+c0hn3tjrh+siY/LCiQyvop2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102A3D1067C099176D6AD43322C3FC7292B35FC5319E12697F3E5BE2ADDB2A612136C12
sha3_384: cf088349edffce7fb8dbe7fb29271c91ba4d7249218ebb128ce0db9d23e7bafc7deceb89b116c0389cd3308cecf908be
ep_bytes: 558bec6aff6844304000682018400064
timestamp: 2009-02-10 07:05:42

Version Info:

0: [No Data]

Graftor.35312 also known as:

BkavW32.AIDetect.malware2
LionicWorm.Win32.Generic.lzlW
MicroWorld-eScanGen:Variant.Graftor.35312
FireEyeGeneric.mg.eea1f3bda7880bc9
CAT-QuickHealTrojan.Rimecud.U
ALYacGen:Variant.Graftor.35312
CylanceUnsafe
K7AntiVirusTrojan ( 0040f0461 )
K7GWTrojan ( 0040f0461 )
Cybereasonmalicious.da7880
BitDefenderThetaGen:NN.ZexaF.34698.gqZ@aCtxJuai
CyrenW32/Rimecud.AL.gen!Eldorado
SymantecTrojan.ADH
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AIDL
TrendMicro-HouseCallTROJ_RIMECUD.SMX
Paloaltogeneric.ml
ClamAVWin.Trojan.Rimecud-16258
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.35312
NANO-AntivirusTrojan.Win32.AutorunerENT.ukktm
CynetMalicious (score: 100)
AvastWin32:Kryptik-JAC [Trj]
TencentWin32.Trojan.Generic.Pgil
Ad-AwareGen:Variant.Graftor.35312
EmsisoftGen:Variant.Graftor.35312 (B)
ComodoWorm.Win32.Palevo.evbs@4pijtx
DrWebWin32.HLLW.AutorunerENT.44048
VIPREGen:Variant.Graftor.35312
TrendMicroTROJ_RIMECUD.SMX
McAfee-GW-EditionPWS-Zbot.gen.aqp
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/HkMain-CT
APEXMalicious
GDataGen:Variant.Graftor.35312
WebrootW32.Trojan.Gen
AviraTR/Crypt.EPACK.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Rimecud.A
GoogleDetected
AhnLab-V3Worm/Win32.Palevo.R28008
McAfeePWS-Zbot.gen.aqp
MAXmalware (ai score=81)
RisingTrojan.Generic@AI.94 (RDML:rihYVOIt2b2V1uueSRL7jw)
FortinetW32/Kryptik.EQMA!tr
AVGWin32:Kryptik-JAC [Trj]
PandaTrj/Rimecud.f
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.35312?

Graftor.35312 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment