Malware

How to remove “Graftor.938087”?

Malware Removal

The Graftor.938087 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.938087 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Thai
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Graftor.938087?


File Info:

name: 822F60111B239FDA90ED.mlw
path: /opt/CAPEv2/storage/binaries/aedebfb228f435d4bac5b71afb7ef5f8a0e6ea4284b337e620e115ae6c4d5ae6
crc32: E63D655F
md5: 822f60111b239fda90ed5c7ae192fd8e
sha1: ea194065ca2255128b63189fb70df87c3f8d95a3
sha256: aedebfb228f435d4bac5b71afb7ef5f8a0e6ea4284b337e620e115ae6c4d5ae6
sha512: 28f987792119e8f80928578e1a8ab0ac1816fe558105a74aaa1c0fb079632a8e7cfa2d2b57e028db8eac0388e1aea4c4ecfcf5c62aa7d6d58400e25b311abdc8
ssdeep: 24576:i4nzZtN3Hl4NXAkzicQ5piIf/dp7hObDbyyvoQ/Oa2Uw6K1qloObC:iazhHSdAkzicAfFpAn1/zy64koC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1215523A6B607C84BDC194373AE92C2B68953BC54BD33932F22C23E7F7E33814A855156
sha3_384: d697d79369996186037ae59d6360691f6c2ebd4b023b2fa259601f34b74d89d966e33d8d44c7adeee4761715790ef040
ep_bytes: 60be15c076008dbeeb4fc9ff5789e58d
timestamp: 2021-09-07 02:11:45

Version Info:

CompanyName: eXtreme Software
FileDescription: eXtreme Trading Launcher Application
ProductName: eXtreme Trading Launcher
ProductVersion: 2021-07-26
Comments:
FileVersion: 1.0.0.11
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
Translation: 0x0409 0x04e4

Graftor.938087 also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanGen:Variant.Graftor.938087
FireEyeGen:Variant.Graftor.938087
McAfeeArtemis!822F60111B23
CylanceUnsafe
ZillyaTrojan.Convagent.Win32.7927
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.6ea0c0e2
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R049C0WL121
Paloaltogeneric.ml
BitDefenderGen:Variant.Graftor.938087
TencentWin32.Trojan.Agent.Dxcx
Ad-AwareGen:Variant.Graftor.938087
EmsisoftGen:Variant.Graftor.938087 (B)
TrendMicroTROJ_GEN.R049C0WL121
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SophosGeneric PUA OK (PUA)
APEXMalicious
JiangminTrojan.Agent.dsod
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.938087
VBA32Trojan.Agent
ALYacGen:Variant.Graftor.938087
MAXmalware (ai score=81)
PandaTrj/CI.A
YandexTrojan.Agent!QL4pAb5S38w
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Graftor.938087?

Graftor.938087 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment