Malware

Graftor.788167 removal

Malware Removal

The Graftor.788167 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.788167 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to create or modify system certificates

How to determine Graftor.788167?


File Info:

name: 9019B45FCE353AB16C54.mlw
path: /opt/CAPEv2/storage/binaries/50490adef7da842fed7ae97ac6b26bb0d132fc640c55e2d5bb3f6ce29bf34528
crc32: 72FEC69A
md5: 9019b45fce353ab16c5469b4131ca9a4
sha1: 5b78b406550dbd71fad31c5659825b142b46aa7b
sha256: 50490adef7da842fed7ae97ac6b26bb0d132fc640c55e2d5bb3f6ce29bf34528
sha512: 8598a02db9955249841cd0bbe1e218bc9cb027934e03e072a0a8e3655ed8047363711e932eae31008629c2b5a6fe8412ba3c949bc24f259da14f207061c3c849
ssdeep: 24576:XHbl/qf1ZTVsdqYuldr689kZ738+hW6FF2MpKpTYuhmBN8BsomiFK/Tn/4b/ivNc:LTWu8u8sFLKpT188bRM/T/WuNz/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198D5AE23B061C4A1C5512AB765E547346EB85B782C79C893EBE0EDB6BC71532C72E30E
sha3_384: 060f15921d46f9b6633fcd54df8c7eff55d0078e863331a8533a228a1469db4db8f54f20f1ee048463aa49cb83e108e9
ep_bytes: 558bec6aff68183a680068545f530064
timestamp: 2022-04-15 19:02:12

Version Info:

0: [No Data]

Graftor.788167 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.788167
McAfeeArtemis!9019B45FCE35
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.fce353
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Graftor.788167
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Graftor.788167
EmsisoftGen:Variant.Graftor.788167 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
TrendMicroTROJ_GEN.R067C0WDN22
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.9019b45fce353ab1
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.agsy
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1DNV50E
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34606.QsW@aOG0kimb
ALYacGen:Variant.Graftor.788167
MAXmalware (ai score=88)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R067C0WDN22
RisingHackTool.GameHack!1.B2A6 (CLOUD)
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen

How to remove Graftor.788167?

Graftor.788167 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment