Malware

Graftor.386666 removal

Malware Removal

The Graftor.386666 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.386666 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.386666?


File Info:

name: 7997DB26D69640D19527.mlw
path: /opt/CAPEv2/storage/binaries/dce6e8216f761d9bae739ba920e4a18b7a0d34d8ffd44e501f50dfb47770f9c7
crc32: 6298A366
md5: 7997db26d69640d195273fa3c38a9488
sha1: 276fad4f72e5f9e93dbab2a19dd4781a483e598d
sha256: dce6e8216f761d9bae739ba920e4a18b7a0d34d8ffd44e501f50dfb47770f9c7
sha512: 390d8d0e56f4bf5beb1738af88cc3aec9b8f80d06fb41eb3287d3c38ed1ae915b905fb4fb76f3d29d2becdd143fead8051d63fc9f6fec20996d7bc5a68eda1e2
ssdeep: 6144:dKAd2cIBioTmi98K9hCqqwXCcLmygTKRxs9NqUMMvA+vBEWo:fdBNKTCqqwXCcdgTL9+MvA+B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2749E113690C076E36627310986E6F556A9BC344AA4E68FF7B83F395E301939A3734F
sha3_384: 9b064f710e1bb1feaf659994178399842711d195868cda60346dcf604fb4a7f4e617fb4c89a450c01fd3ea1337ea2188
ep_bytes: e9560b00000058055a0b00008b3003f0
timestamp: 2013-10-14 12:10:28

Version Info:

0: [No Data]

Graftor.386666 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.386666
ClamAVWin.Packed.Urelas-9879149-0
FireEyeGeneric.mg.7997db26d69640d1
McAfeeArtemis!7997DB26D696
CylanceUnsafe
SangforWorm.Win32.Save.a
Cybereasonmalicious.6d6964
BitDefenderThetaGen:NN.ZexaF.34646.wmW@aeGpR!bO
CyrenW32/Urelas.AP.gen!Eldorado
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.W
BaiduWin32.Trojan.Urelas.a
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.GenericCryptor.czx
BitDefenderGen:Variant.Graftor.386666
AvastWin32:Dropper-OAF [Drp]
TencentRansom.Win32.CryLock.a
Ad-AwareGen:Variant.Graftor.386666
SophosMal/Generic-S
ComodoTrojWare.Win32.Gupboot.BB@53dg1h
DrWebTrojan.AVKill.33464
VIPREGen:Variant.Graftor.386666
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.386666 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1HZEHYG
JiangminTrojan/Refroso.afgk
WebrootTrojan.Dropper
AviraHEUR/AGEN.1215489
Antiy-AVLTrojan/Generic.ASCommon.177
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Ransom.R200546
Acronissuspicious
ALYacGen:Variant.Graftor.386666
MAXmalware (ai score=80)
MalwarebytesUrelas.Spyware.Stealer.DDS
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexPacked/MPress
IkarusTrojan.Win32.Toga
MaxSecureTrojan.Malware.11606240.susgen
FortinetW32/Urelas.AE!tr
AVGWin32:Dropper-OAF [Drp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Graftor.386666?

Graftor.386666 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment