Malware

Graftor.950076 removal tips

Malware Removal

The Graftor.950076 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.950076 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Graftor.950076?


File Info:

name: 3B0DF21E8390C509EAB8.mlw
path: /opt/CAPEv2/storage/binaries/c4fa5f4ebc5785ac1a419330ac0ea58b43408a0847ba7cf96e7bd8978e3d5b8b
crc32: 30DCA8A8
md5: 3b0df21e8390c509eab8e09148eb0d42
sha1: ff860d5494473db1aeb949c149129a05c9df419a
sha256: c4fa5f4ebc5785ac1a419330ac0ea58b43408a0847ba7cf96e7bd8978e3d5b8b
sha512: d19e9f3d48249ce110ebf691bb1eada701a7395cf100dd6b64b5bd339cf489823a26a1a4bbec585c9d839c68437fd48183749bc157efb4ba8df1e22aea63fc05
ssdeep: 1536:/KbzDhV6MMjMUKiZaKAJH/K3vCclW1URov0CmuJd4BXKikc6C:/KbzVa/XQKApK/vESRiBbd4M5C
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14893020AC3814DD4E9306BFB99B76EC9A100D020A51DE343D974DEF86E9A6E4D6CC60B
sha3_384: 1a160d9a4390d024f76de79752e918099ff2b32b02d1cdd33c06d41f119b75357a0264bff2fc0ed2d2fe5022f0cbc34a
ep_bytes: ba0000000083ec04893c2409f301f68b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Graftor.950076 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.950076
ClamAVWin.Packed.Copak-9853643-0
FireEyeGeneric.mg.3b0df21e8390c509
McAfeeGenericRXAA-FA!3B0DF21E8390
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Copak.49106622
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.494473
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Graftor.950076
NANO-AntivirusTrojan.Win32.Kryptik.ilkwfd
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.hb
Ad-AwareGen:Variant.Graftor.950076
SophosML/PE-A + Troj/Agent-BGZJ
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Graftor.950076
McAfee-GW-EditionBehavesLike.Win32.VirRansom.nc
EmsisoftGen:Variant.Graftor.950076 (B)
IkarusTrojan.Kryptik
GDataGen:Variant.Graftor.950076
JiangminTrojan.Copak.avs
AviraHEUR/AGEN.1200606
Antiy-AVLTrojan/Generic.ASBOL.C686
ArcabitTrojan.Graftor.DE7F3C
MicrosoftTrojan:Win32/Sabsik.TE.A!ml
GoogleDetected
AhnLab-V3Malware/Gen.RL_Reputation.R366989
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.fmZ@aqxLbnk
ALYacGen:Variant.Graftor.950076
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Graftor.950076?

Graftor.950076 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment