Malware

Graftor.487170 (B) information

Malware Removal

The Graftor.487170 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.487170 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.487170 (B)?


File Info:

name: D18C37DA3FB143A6A7E5.mlw
path: /opt/CAPEv2/storage/binaries/38719ee200a3e15a0081f421ebee6beafa4a7e57c3578fcc4671bdb557371e71
crc32: CCD05FD4
md5: d18c37da3fb143a6a7e514db56a1d9d1
sha1: ffb1d7c6450f107140037be0bd63d377d9d4df8f
sha256: 38719ee200a3e15a0081f421ebee6beafa4a7e57c3578fcc4671bdb557371e71
sha512: a73e582174bc7f2007be04625d22ef1caec65be244a5c733e12fad239e58558fff0778bee0cd40b5832b59fa5afe3cb534fc5ac70b7e4c669d3b41200558887e
ssdeep: 24576:z8GSeK9LnAVp3fK6wqtGAxInG8En3XVvO:ztKeVp3fKwGKMtE3Fv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F01523496BCDAF2CD240BA397133BB35D1C21B703046C9BB60E1AD944522BA5E964FDF
sha3_384: c00c7cdf9376dd800575518b81a499c07a9b8516fa585f7d1ace746b53530108427963463fc9b85ede833bbb92235154
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2020-09-05 19:28:58

Version Info:

CompanyName: 761魔域登录器
FileDescription: 商业程序
InternalName: mydlq.exe
LegalCopyright: 版权所有 (C) 2010
OriginalFilename: LoginTools.exe
ProductName: 商业程序
ProductVersion: 1, 0, 0, 0
FileVersion: 1,0,0,0
Translation: 0x0804 0x03a8

Graftor.487170 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Hosts.48206
MicroWorld-eScanGen:Variant.Graftor.487170
FireEyeGeneric.mg.d18c37da3fb143a6
CAT-QuickHealTrojan.Vindor
Cylanceunsafe
ZillyaTool.GameTool.Win32.1434
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0054406b1 )
AlibabaMalware:Win32/km_2ebce5.None
K7GWRiskware ( 0054406b1 )
Cybereasonmalicious.a3fb14
BitDefenderThetaGen:NN.ZelphiF.36350.3S0ba88IDOci
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.GameTool.T
CynetMalicious (score: 100)
TrendMicro-HouseCallTROJ_GEN.R011C0DHP23
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-PSW.Win32.Pycoon.gen
BitDefenderGen:Variant.Graftor.487170
NANO-AntivirusTrojan.Win32.Hosts.ihshyl
TencentRiskware.Win32.Gametool.16000715
EmsisoftGen:Variant.Graftor.487170 (B)
VIPREGen:Variant.Graftor.487170
TrendMicroTROJ_GEN.R011C0DHP23
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.PSE.10SL7FA
Antiy-AVLRiskWare/Win32.GameTool
ArcabitTrojan.Graftor.D76F02
ZoneAlarmHEUR:Trojan-PSW.Win32.Pycoon.gen
MicrosoftTrojan:Win32/Vindor!pz
AhnLab-V3Malware/Win.Generic.R480295
Acronissuspicious
VBA32TScope.Trojan.Delf
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
APEXMalicious
RisingStealer.Pycoon!8.1340C (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Lmir.BQT!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Graftor.487170 (B)?

Graftor.487170 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment