Malware

Graftor.632498 malicious file

Malware Removal

The Graftor.632498 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.632498 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.632498?


File Info:

name: 628A7CE05D3C370CDE13.mlw
path: /opt/CAPEv2/storage/binaries/8e7e3b4a14d37612062912860491816866f6c60611d092942cca4b1c72ac1546
crc32: 33C581BC
md5: 628a7ce05d3c370cde1386542fdb57a8
sha1: 09f742eace70ced8ce7919d9fa4076a00c382086
sha256: 8e7e3b4a14d37612062912860491816866f6c60611d092942cca4b1c72ac1546
sha512: b5b5a9224caa482658d4e5d76f0a95b8755f8719a1a15844c133b53e664977202b8eba1db86ba783509471a912effa5e3cc238e09bc02d70444ab507a4a3b27b
ssdeep: 1536:Cv6GPNTycNy7fG012j0+uCgyh8rOiuF4ZAk/hagopzz4LLFlU308wIZkF4XhY7:WTVNyYj3uCB0ago9z4vM3v8YhA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE256D26F6819076D4220AF8D91FC2D8E53939302D3CAA47BAEA5F4DFD77291211D2C7
sha3_384: 5c2a385df7a19a6deef93583f229dca8914765fe430c70b49d76b3b24902c2ae3c1be52fbd7003517c275e667803a25c
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.632498 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.61273
MicroWorld-eScanGen:Variant.Graftor.632498
ClamAVWin.Trojan.Netmail-9844929-0
FireEyeGeneric.mg.628a7ce05d3c370c
McAfeeArtemis!628A7CE05D3C
MalwarebytesMalware.AI.693497512
VIPREGen:Variant.Graftor.632498
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.05d3c3
BitDefenderThetaGen:NN.ZelphiF.36164.8GW@aqKT51p
CyrenW32/Banker.HW.gen!Eldorado
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.NetMail.a
BitDefenderGen:Variant.Graftor.632498
AvastWin32:Trojan-gen
TACHYONBackdoor/W32.DP-NetMail.988160
EmsisoftGen:Variant.Graftor.632498 (B)
F-SecureTrojan.TR/Zusy.9881605548
ZillyaBackdoor.NetMail.Win32.1
McAfee-GW-EditionGenericRXVH-RZ!628A7CE05D3C
Trapminesuspicious.low.ml.score
SophosTroj/Agent-BCNT
GDataWin32.Trojan-Stealer.Banker.AK
JiangminBackdoor/NetMail.a
AviraTR/Zusy.9881605548
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Graftor.D9A6B2
ZoneAlarmBackdoor.Win32.NetMail.a
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Backdoor/Win.NetMail.R559025
ALYacGen:Variant.Graftor.632498
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (TFE:4:iWNbawThGVF)
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.2991593.susgen
FortinetW32/Banker.WGA!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Graftor.632498?

Graftor.632498 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment