Malware

Graftor.6733 (file analysis)

Malware Removal

The Graftor.6733 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.6733 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.6733?


File Info:

name: 066C18A1419DA72B169B.mlw
path: /opt/CAPEv2/storage/binaries/329359c3d1af4bbf9d25e53bec86a65bd18664e118bd18e5f17ef8d924dfc8e2
crc32: ADB23D5E
md5: 066c18a1419da72b169beb9797533ac0
sha1: 36e2c3ef49e29afc35da6898e0f15752e3126e46
sha256: 329359c3d1af4bbf9d25e53bec86a65bd18664e118bd18e5f17ef8d924dfc8e2
sha512: 0e71ab8531f1b9066431d9580dc1b8eb28065966f51670deca6e7fde34a4174328969fd024ed68ad5721bc95b69312a6d84b35533a8c0506ddd08d06b46b5797
ssdeep: 49152:SQ6ubyGZoLCrRJrEUnmjPVXbLUBomrRJrEUnmjPoa:NRyGZoL2uUmXbSuUVa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121D5CF12B3C5C0B2C55615316ABA677B6A39B6610B34C7C3E390CDBD6D312D2EA3631B
sha3_384: 2b516517382526a258016fccfc6e60e9231d9292f14009229cf74e7a30e003ed06fe5e5cb0cde64456a672bd7f3b368f
ep_bytes: 558bec6aff6890a35d00684c65460064
timestamp: 2015-07-17 10:31:58

Version Info:

0: [No Data]

Graftor.6733 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.mCU1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.6733
FireEyeGeneric.mg.066c18a1419da72b
McAfeeArtemis!066C18A1419D
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRiskWare:Win32/StartPage.da1d9504
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BaiduWin32.Trojan.FlyStudio.py
CyrenW32/VBInject.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.MHABGAM potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.StartPage.fy
BitDefenderGen:Variant.Graftor.6733
NANO-AntivirusTrojan.Win32.BlackHole.dwympa
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Graftor.6733
EmsisoftGen:Variant.Graftor.6733 (B)
DrWebBackDoor.BlackHole.29389
VIPRETrojan.Win32.Generic!BT
SophosGeneric PUA DG (PUA)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
ArcabitTrojan.Graftor.D1A4D
MicrosoftTrojan:Win32/Wacatac.A!ml
ALYacGen:Variant.Graftor.6733
VBA32BScope.Backdoor.IRC.Bot
MalwarebytesMalware.Heuristic.1004
RisingTrojan.Injector!1.A1C3 (CLOUD)
YandexRiskware.StartPage!JpPTx1Z/2+s
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/StartPage
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Graftor.6733?

Graftor.6733 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment