Malware

Graftor.551024 removal instruction

Malware Removal

The Graftor.551024 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.551024 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Graftor.551024?


File Info:

name: 405E283186CC6139DB0C.mlw
path: /opt/CAPEv2/storage/binaries/2009fd744f6af2897ce133dbf28be7b2999f90a8ca18a5dda0485dd68def6fb9
crc32: 4E85E489
md5: 405e283186cc6139db0cb1d7d3f15a1e
sha1: 541819752501a30c2bfa00bf1ccd500d680c8d4a
sha256: 2009fd744f6af2897ce133dbf28be7b2999f90a8ca18a5dda0485dd68def6fb9
sha512: 2b981522b5f6be490d32a82f62cea3d6f18bd85e57ce8d0499f530859854fb06051872d97d96bbeafd5b8c709e4e28b4087d3ccbce7be84a610592abb28dcf36
ssdeep: 12288:bbT3pTSlvZ0yeZol9/ZvgeDK6kpPTZwYiDU911tUSM3CE:bbT3Ux0bZ0vgOK0A911tZMH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF458E01B58684F2D5415A3004AAE73AEE399E4A4B36CB8397D8FE3FBC731D19732255
sha3_384: 39d5e7a54bf59be199fc170637adb75b6f94a13a9cb46c7e8b99602b4aaa0322ad9f85da620449ba7efffcc143e398a5
ep_bytes: 558bec6aff6818904e006814dc490064
timestamp: 2022-01-25 06:00:01

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: [仙居阁]科技与未来
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Graftor.551024 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.551024
FireEyeGeneric.mg.405e283186cc6139
ALYacGen:Variant.Graftor.551024
MalwarebytesTrojan.MalPack.FlyStudio
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.551024
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.186cc6
BitDefenderThetaGen:NN.ZexaF.34182.lr0@am8ABglb
CyrenW32/Agent.EW.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
ClamAVWin.Trojan.Generic-9909895-0
KasperskyUDS:Trojan.Win32.FlyStudio.gen
Ad-AwareGen:Variant.Graftor.551024
EmsisoftGen:Variant.Graftor.551024 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
SophosMal/Generic-S
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik!ml
ZoneAlarmHEUR:Trojan.Win32.FlyStudio.gen
GDataWin32.Trojan.PSE.1THOGOA
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!405E283186CC
VBA32BScope.TrojanPSW.Fareit
CylanceUnsafe
APEXMalicious
RisingHackTool.GameHack!1.B2A6 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Application
PandaTrj/GdSda.A

How to remove Graftor.551024?

Graftor.551024 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment