Malware

Should I remove “Graftor.54481”?

Malware Removal

The Graftor.54481 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.54481 virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Graftor.54481?


File Info:

name: 6D3914027E5E404F1B90.mlw
path: /opt/CAPEv2/storage/binaries/8776f4ceaa48bbdbe905e732510c640e5c42c06e957b6f15068498c31a9e71b0
crc32: 7C4DD1BA
md5: 6d3914027e5e404f1b9059170d70d0f3
sha1: 075107160d0676adcee0887ec81998c18a674c75
sha256: 8776f4ceaa48bbdbe905e732510c640e5c42c06e957b6f15068498c31a9e71b0
sha512: 32d49eabd1aab53391cb1d204f250ff109e179f75931137a0c05842f09f5e39612332db9e03fc594da7103eadb48cb36d9994a85b755279a6b0772f37ef9fe73
ssdeep: 3072:ltIIHxWJH+jc/c9Yd6Ir32dwwAwEC6UttSbY7B3+1fAjPEIhnwMeOvepR2+rHzoh:l+IHIfc9ej2zEC64N3vj6p0+rTob/mU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD2412579DE58CBEC220CF3FA85E7E4E93D8DB090C00E282C6955DC96C6E3DA892F445
sha3_384: 127c1fa4a62795df30cf15ef384cee3e6a42b951531002c740b7a825755a4c917c35ca1dd9275260172b9ef21612902e
ep_bytes: 558bec83c4f0b828404000e880f6ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.54481 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.lzwQ
MicroWorld-eScanGen:Variant.Graftor.54481
FireEyeGeneric.mg.6d3914027e5e404f
ALYacGen:Variant.Graftor.54481
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c31 )
K7GWTrojan ( 0040f2c31 )
Cybereasonmalicious.27e5e4
CyrenW32/Zbot.TF.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.YZG
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.54481
NANO-AntivirusTrojan.Win32.Inject.dcjdcf
AvastWin32:Crypt-OJN [Trj]
TencentWin32.Trojan.Inject.bpjl
Ad-AwareGen:Variant.Graftor.54481
EmsisoftGen:Variant.Graftor.54481 (B)
ComodoMalware@#3obdgg6vbmfif
DrWebTrojan.DownLoader7.47742
ZillyaTrojan.Inject.Win32.59539
TrendMicroTSPY_ZBOT.SM16
McAfee-GW-EditionPWS-Zbot.gen.aow
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/DfCheMan-D
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Graftor.54481
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.ZPACK.Gen8
MAXmalware (ai score=88)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Graftor.DD4D1
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.C159234
McAfeePWS-Zbot.gen.aow
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMachineLearning/Anomalous.95%
TrendMicro-HouseCallTSPY_ZBOT.SM16
RisingTrojan.Generic@AI.100 (RDML:zEh7BHYfVnVpvJYXFpO1cA)
YandexTrojan.Inject!QwXZWDAbfog
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.WCT!tr
BitDefenderThetaAI:Packer.D5EBB3E021
AVGWin32:Crypt-OJN [Trj]
PandaTrj/Velphi.b
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.54481?

Graftor.54481 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment