Malware

Graftor.678 removal guide

Malware Removal

The Graftor.678 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.678 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates known PcClient mutex and/or file changes.

How to determine Graftor.678?


File Info:

name: 4B1914ECB0BE76431481.mlw
path: /opt/CAPEv2/storage/binaries/45e24e5f04d83213f47b47486785a481b575ec5f415bec715676b5f520dc0e8a
crc32: C09D0926
md5: 4b1914ecb0be7643148135dd67a44852
sha1: b3cce86dc8917eed5615abd0471955eaf605f2ce
sha256: 45e24e5f04d83213f47b47486785a481b575ec5f415bec715676b5f520dc0e8a
sha512: de1b856786e5f97299081a3028bcc0b4d9c835266cd36ef22f802fd18d79f4d2ed13fad833ddba756d7ba958d2f0227862e7f58912e347b85b5520ae4559bee8
ssdeep: 384:xuxpIu9L1816d7faDLgcvCUVkFmWVSi42/Qx:xuxp38cf0gcvgFN/J/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F823B03ED044AF7CC44827060A3294DE5705C730BA55D2F6F6DEEAC2EB869279B764E
sha3_384: 7cc58280dead8ea205c8bd865039a26ece2f218bb3a1549ab749c47782b274c6553a73bf4a5dae9a544c6af3783c0e9d
ep_bytes: 558bec6aff681015400068961c400064
timestamp: 2011-05-26 13:35:48

Version Info:

0: [No Data]

Graftor.678 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Magania.lepg
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader3.7934
MicroWorld-eScanGen:Variant.Graftor.678
FireEyeGeneric.mg.4b1914ecb0be7643
CAT-QuickHealDownloader.Small.11945
SkyhighBehavesLike.Win32.PWSZbot.lm
ALYacGen:Variant.Graftor.678
Cylanceunsafe
VIPREGen:Variant.Graftor.678
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 002b6c9a1 )
BitDefenderGen:Variant.Graftor.678
K7GWTrojan-Downloader ( 002b6c9a1 )
Cybereasonmalicious.dc8917
ArcabitTrojan.Graftor.678
BitDefenderThetaGen:NN.ZexaF.36792.biW@auvI0Ueb
VirITTrojan.Win32.Generic.BOJA
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Small.PJP
APEXMalicious
ClamAVWin.Trojan.Small-20870
KasperskyTrojan-Dropper.Win32.Small.hms
AlibabaTrojanDownloader:Win32/Lepasud.e55c7ec3
NANO-AntivirusTrojan.Win32.Small.dlprwb
RisingTrojan.DL.Win32.Undef.thl (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Downloader.Gen
ZillyaDropper.Small.Win32.7527
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Graftor.678 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=100)
JiangminTrojanDropper.Small.fam
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Downloader.Gen
VaristW32/Downloader-Sml!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.Small
KingsoftWin32.Troj.Undef.a
XcitiumSuspicious@#pip44ks120tg
MicrosoftTrojanDownloader:Win32/Small.gen!F
ZoneAlarmTrojan-Dropper.Win32.Small.hms
GDataGen:Variant.Graftor.678
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R6140
McAfeeGenericR-DNR!4B1914ECB0BE
TACHYONTrojan/W32.Small.17920.KW
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Tiggre
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
TencentTrojan.Win32.FakeLpk.mc
YandexTrojan.GenAsa!7lvEq0vKGdc
IkarusTrojan-PSW.OnlineGames
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Small.HMS!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.678?

Graftor.678 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment