Malware

Graftor.538546 (file analysis)

Malware Removal

The Graftor.538546 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.538546 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Graftor.538546?


File Info:

crc32: 4A91A8F9
md5: a0d9a40e2918269cd23bc77c2bf358e0
name: A0D9A40E2918269CD23BC77C2BF358E0.mlw
sha1: 78cae63960ff9a0a04142458196971d97c78248a
sha256: c219653a34d837d98af67dca9ce2ff47ab675c9008def63b8978a2e94de147c0
sha512: 2afa9fe32ce0242c9870e21af821aa3565881afcc4d296be61c4595c3e6e5c9d8b9911015a74d8b1f1a16567975ee434fd3d117a40e68087a7700702daa409b4
ssdeep: 1536:jmANLS72foZybhFgLgWQUCwxF+0MDq75WZDXUFFUK7SYiOBTFMExxfspFGieQD0O:jrPfo8b3gEtkaUAK+riFMELeVeQoO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.538546 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004c9f371 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Farfli
ALYacGen:Variant.Graftor.538546
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Farfli.a19b582c
K7GWTrojan ( 004c9f371 )
Cybereasonmalicious.e29182
CyrenW32/Trojan.OHZM-5593
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BLQC
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderGen:Variant.Graftor.538546
MicroWorld-eScanGen:Variant.Graftor.538546
Ad-AwareGen:Variant.Graftor.538546
SophosMal/Generic-S
ComodoTrojWare.Win32.Kryptik.WN@4p3oqw
BitDefenderThetaGen:NN.ZexaF.34738.iyX@am0SSplb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R005C0WFC21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.a0d9a40e2918269c
EmsisoftGen:Variant.Graftor.538546 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1107367
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult!ml
AegisLabTrojan.Win32.Farfli.m!c
GDataGen:Variant.Graftor.538546
AhnLab-V3Malware/Win.Generic.C4525979
Acronissuspicious
McAfeeGenericRXOW-CS!A0D9A40E2918
MAXmalware (ai score=80)
VBA32suspected of Malware.Agent.22
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R005C0WFC21
RisingTrojan.Generic@ML.96 (RDML:AqYPTjUMu4wE3zAMLbyxfg)
YandexTrojan.GenAsa!Ox+dBMgUVXs
IkarusTrojan.Win32.Injector
FortinetW32/BLQC!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Graftor.538546?

Graftor.538546 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment