Malware

Graftor.639328 information

Malware Removal

The Graftor.639328 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.639328 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Graftor.639328?


File Info:

name: D10FF620B8262D7AB261.mlw
path: /opt/CAPEv2/storage/binaries/2cf856396a4a790ee8e48457ab293cc8be044ead056ea9de085b39af04ccaed5
crc32: 38462ECB
md5: d10ff620b8262d7ab2616106026a3005
sha1: f16e9bb2177f6b37ed1af9c422e85f320958323e
sha256: 2cf856396a4a790ee8e48457ab293cc8be044ead056ea9de085b39af04ccaed5
sha512: bbd443b861d6b217ab1e6d92ca6ed82e82f010cc2e1976e27290fbf95a7004b5ac90fb96d3b85ff278362e9862d657d938e5d06dff09fc0fb1cd2e23ca4c251b
ssdeep: 6144:8HVVUXcILPlAvgHYL6r1/nmZQcfeNIBAhgrJrFdr4n6KUiJh6YP+A5+x+e6pvh2j:+k53AU0/JmElC6YP+xnY2/Ib76xHL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6B4B2E4C9672A7AE777CB5BC9AB3D3D8E002377BE53A49B003431951562282EF4251F
sha3_384: 8e991a45f7bc4ebc0ea3536940db776c29564480bc9d9a875afbb84892bb146a016ff3bd2a346c836193b792a26a6f57
ep_bytes: 60be00a041008dbe0070feff57eb0b90
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

Graftor.639328 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Unruy.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.639328
FireEyeGeneric.mg.d10ff620b8262d7a
CAT-QuickHealDownloader.Unruy.16638
SkyhighBehavesLike.Win32.Generic.hm
McAfeeGenericRXMN-SQ!B91BEE0C6CF4
MalwarebytesUnruy.Trojan.Downloader.DDS
VIPREGen:Variant.Graftor.639328
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 001156081 )
K7GWTrojan-Downloader ( 001156081 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Clicker.Cycler.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
APEXMalicious
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.gen
BitDefenderGen:Variant.Graftor.639328
NANO-AntivirusTrojan.Win32.Unruy.ibnpwx
AvastWin32:Unruy-AA [Trj]
RisingDownloader.Unruy!1.AE5E (CLASSIC)
EmsisoftGen:Variant.Graftor.639328 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.22
ZillyaDownloader.Unruy.Win32.7662
Trapminemalicious.moderate.ml.score
SophosTroj/Cycler-C
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.glpgv
VaristW32/Unruy.N.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Downloader]/Win32.Unruy
Kingsoftmalware.kb.b.994
MicrosoftTrojan:Win32/Cycler!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Graftor.D9C160
ZoneAlarmHEUR:Trojan-Clicker.Win32.Cycler.gen
GDataWin32.Trojan.PSE.4PGMWY
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Unruy.1355704
Acronissuspicious
VBA32BScope.TrojanDownloader.Unruy
ALYacGen:Variant.Graftor.639328
Cylanceunsafe
TencentTrojan.Win32.Unruy.wa
YandexTrojan.GenAsa!S4Mv8DNs2+w
IkarusTrojan-Downloader.Win32.Unruy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Cycler.TL!tr
BitDefenderThetaGen:NN.ZexaF.36802.GmJfaO5ABbj
AVGWin32:Unruy-AA [Trj]
Cybereasonmalicious.0b8262
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Unruy

How to remove Graftor.639328?

Graftor.639328 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment