Malware

How to remove “Graftor.375178”?

Malware Removal

The Graftor.375178 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.375178 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic

How to determine Graftor.375178?


File Info:

crc32: 69FF7425
md5: b6708490f6504ca84f52850f9cb4eace
name: B6708490F6504CA84F52850F9CB4EACE.mlw
sha1: 17927cb1008d83a0bdceda3348d16d169da8e49a
sha256: b342733971e34b3b1a380aebf1b2034f8bb1cbb8d50d376657e02792161523f3
sha512: 8d27d58f748878f210b13f4afdcc6f0bda3d8df72cc5d41fed73feb29f4cd3d81e66cc432a997dd3b3ae6147eac376b49f7cfa98a106c03a8bfaa36bc3b7755e
ssdeep: 192:kDii0Gf6za+WKJcoIpMvLclg5pd9KITwy+TAX:cibWMa+fJcPpMTcl6KITwysAX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1, 0, 0, 1
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Graftor.375178 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.55041
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.375178
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.33257
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0f6504
SymantecBackdoor.Contopee
ESET-NOD32a variant of Win32/NukeSped.AF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Contopee-1
KasperskyTrojan-Ransom.Win32.Blocker.embr
BitDefenderGen:Variant.Graftor.375178
NANO-AntivirusTrojan.Win32.Blocker.ddapph
ViRobotTrojan.Win32.Agent.24584[UPX]
MicroWorld-eScanGen:Variant.Graftor.375178
TencentWin32.Trojan.Blocker.Pfiu
Ad-AwareGen:Variant.Graftor.375178
ComodoWorm.Win32.Prux.A@4q442u
BitDefenderThetaAI:Packer.46F2B0A31F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.xh
FireEyeGeneric.mg.b6708490f6504ca8
EmsisoftGen:Variant.Graftor.375178 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.ajn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.B4DB04
GDataGen:Variant.Graftor.375178
TACHYONRansom/W32.Blocker.24584
AhnLab-V3Trojan/Win32.Agent.R169506
Acronissuspicious
McAfeeArtemis!B6708490F650
MAXmalware (ai score=81)
VBA32Hoax.Blocker
PandaTrj/Genetic.gen
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!ecVivocviXg
FortinetW32/Generic.AC.219AED!tr
AVGWin32:Malware-gen

How to remove Graftor.375178?

Graftor.375178 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment