Malware

Graftor.64700 (B) (file analysis)

Malware Removal

The Graftor.64700 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.64700 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Graftor.64700 (B)?


File Info:

name: 62A5C4E85DD3DFB85DFC.mlw
path: /opt/CAPEv2/storage/binaries/7f422390b2ad33807da9760139306b6de44013ae56d460b154cde32c4b5490a0
crc32: CDC7AD26
md5: 62a5c4e85dd3dfb85dfc5fb299a56ff7
sha1: b368766c8d291a06c352748231f34eb6bab349af
sha256: 7f422390b2ad33807da9760139306b6de44013ae56d460b154cde32c4b5490a0
sha512: 74a4626e16b30ecbf5365b26eb66a08dc6d9aa23f23ce54a4309721bd97ce20600b44b4322ec52d803d3e1cf5bfcc5a3d0ba03a01b9dc5ed787c62250507e17f
ssdeep: 12288:p/3aUuMs2MXcXaRQ8wqKhb43nLl5tDrXa:p/3zUcKy8wvhb43pD2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BC4CF013640C036E36AAB714946EAB55EA57D3499B0E64FF7647E3A5E301436B3B30F
sha3_384: f55e32f9306272bd3c443ffe4f308e446ce34e42ae8335ba20886dbb1fc9bc833a7a5290ad3fb6d45f2cacbc1ae34480
ep_bytes: c1886c411395fb8dca97f811e9efecbd
timestamp: 2013-10-21 11:44:58

Version Info:

0: [No Data]

Graftor.64700 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.64700
ClamAVWin.Packed.Urelas-9879149-0
McAfeeGenericRXVW-KY!62A5C4E85DD3
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Graftor.64700
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.85dd3d
BaiduWin32.Trojan.Urelas.a
CyrenW32/Urelas.ED.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Graftor.64700
TencentTrojan.Win32.Urelas.16000132
EmsisoftGen:Variant.Graftor.64700 (B)
F-SecureTrojan.TR/Patched.Ren.Gen2
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.62a5c4e85dd3dfb8
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.64700
AviraTR/Patched.Ren.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
XcitiumTrojWare.Win32.Gupboot.BB@53dg1h
ArcabitTrojan.Graftor.DFCBC
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZexaCO.36250.KmZ@aCiDB7i
ALYacGen:Variant.Graftor.64700
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CFG23
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.AP!dam
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.64700 (B)?

Graftor.64700 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment