Malware

About “Graftor.636412” infection

Malware Removal

The Graftor.636412 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.636412 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Graftor.636412?


File Info:

name: 151CA31C9648951EAD56.mlw
path: /opt/CAPEv2/storage/binaries/d0cdb6f5bb478b987b87163116e15de2a3ad0b59d803791605b1efa3584ca614
crc32: 88820D88
md5: 151ca31c9648951ead567b3d224f7ce1
sha1: 1e4e7776050e74dbc862771621dc046b1a9b76ee
sha256: d0cdb6f5bb478b987b87163116e15de2a3ad0b59d803791605b1efa3584ca614
sha512: ea4dd926512f55e1bcd633e2ed968447d1d59c1e1b71dcda1a252a4665f9b7da306b659d599ae5b87d846a1c23d240eb6ba036110b67d6438237b7e20424dccd
ssdeep: 6144:KmjUslrcpojXbZK0po+P1ykrAw/7hoJr9lB7iVu:Km4slIshYk52Eu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132A4B06099766F3AF77BDA7F4C9E79198B1533B3BB43A1CB042461970562292BF0210F
sha3_384: a78599cbbc28986c7929b0a6d98a0c0c2e9dccffc673fd6f5dd7d63023e2b023dbaf876514af90c1ecffd3a5022bd0a2
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

Graftor.636412 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Cycler.tqY4
tehtrisGeneric.Malware
DrWebWin32.HLLC.Asdas.22
MicroWorld-eScanGen:Variant.Graftor.636412
FireEyeGeneric.mg.151ca31c9648951e
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gt
ALYacGen:Variant.Graftor.636412
Cylanceunsafe
ZillyaDownloader.Unruy.Win32.7775
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanDownloader:Win32/Unruy.04f55fbb
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c96489
BitDefenderThetaGen:NN.ZexaF.36802.DmZ@aelUL9i
SymantecW32.Unruy.A
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
APEXMalicious
TrendMicro-HouseCallTROJ_UNRUY.SMT
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.gen
BitDefenderGen:Variant.Graftor.636412
NANO-AntivirusTrojan.Win32.GenKryptik.fnqhed
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
AvastWin32:Unruy-AA [Trj]
TencentTrojan.Win32.Unruy.wa
EmsisoftGen:Variant.Graftor.636412 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan-Clicker.Cycler.a
VIPREGen:Variant.Graftor.636412
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
SophosTroj/Unruy-O
IkarusTrojan-Downloader.Win32.Unruy
GDataWin32.Trojan.PSE.RE8W1H
JiangminTrojan.Generic.glpgv
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Unruy.N.gen!Eldorado
Antiy-AVLTrojan[Clicker]/Win32.Cycler
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Graftor.D9B5FC
ZoneAlarmHEUR:Trojan-Clicker.Win32.Cycler.gen
MicrosoftTrojanDownloader:Win32/Unruy!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Unruy.C5602215
Acronissuspicious
McAfeeGenericRXMN-SQ!151CA31C9648
MAXmalware (ai score=86)
VBA32Trojan.Azden
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDownloader.Unruy!1.AE5E (CLASSIC)
YandexTrojan.GenAsa!S4Mv8DNs2+w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/UNRUY.BK!tr
AVGWin32:Unruy-AA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[downloader]:Win/Unruy

How to remove Graftor.636412?

Graftor.636412 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment