Malware

Graftor.675254 removal guide

Malware Removal

The Graftor.675254 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.675254 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.675254?


File Info:

name: 83D03020D812D87A68D8.mlw
path: /opt/CAPEv2/storage/binaries/8e947aa5e13b3ef96ca3d536fbc5917bed1960ab430763498ff6fd18905cb308
crc32: E648CA3C
md5: 83d03020d812d87a68d8e454ac87d850
sha1: 82569928d02b192b8358e2a1c4fffc6332d41008
sha256: 8e947aa5e13b3ef96ca3d536fbc5917bed1960ab430763498ff6fd18905cb308
sha512: 4e838faa054cf7d0d247eb9de0b006363a72a5274fca527ac082c0ec41faed06c74afb7c79b1e3221bd69cccb85a68cbc10b4e112600fb0b945b13740c41a48f
ssdeep: 6144:+30L4EWHJD7l3ITn3ohTm5pPMaYy6BCrNQWh:n4Ewhm4RmTUBCBx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117140115790B66F2D872C9BC8E73E2314428AE72EDC046D3BADD1E58F0912D7272572E
sha3_384: 7b9db48aa5df8d2ab9af341ce8c6af316a175510c6d8e2a05195738734403e25cf568bc3ce14758bd46cbf7bce7f7599
ep_bytes: 833defd04200fd8b05f0d0420085c074
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.675254 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lxlK
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.2363
MicroWorld-eScanGen:Variant.Graftor.675254
FireEyeGeneric.mg.83d03020d812d87a
CAT-QuickHealTrojan.Kanots.A
ALYacGen:Variant.Graftor.675254
ZillyaTrojan.Zbot.Win32.62635
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/EncPk.7550bc93
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.0d812d
BitDefenderThetaGen:NN.ZexaF.34212.mGX@aqKPTFfk
VirITTrojan.Win32.Generic.CNOD
CyrenW32/Zbot.QM.gen!Eldorado
SymantecPacked.Generic.382
ESET-NOD32Win32/Spy.Zbot.YW
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.675254
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:Susn-AU [Trj]
TencentMalware.Win32.Gencirc.114c3d2a
Ad-AwareGen:Variant.Graftor.675254
ComodoTrojWare.Win32.Spy.ZBot.EACK@4pmhx4
BaiduWin32.Virus.Krap.a
VIPRETrojan.Win32.Generic!BT
EmsisoftGen:Variant.Graftor.675254 (B)
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Graftor.675254
JiangminTrojan/Birele.bdm
MaxSecureTrojan.Malware.300983.susgen
AviraDR/Delphi.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.502E0
MicrosoftPWS:Win32/Zbot
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.Zbot.R27819
Acronissuspicious
McAfeePWS-Zbot.gen.bdn
TACHYONTrojan-Spy/W32.ZBot.199681
VBA32TrojanSpy.Zbot
APEXMalicious
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.GenAsa!NBaBu86kvbk
MAXmalware (ai score=100)
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.EQPB!tr
AVGWin32:Susn-AU [Trj]
PandaTrj/Pacrypt.D
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Graftor.675254?

Graftor.675254 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment