Malware

Graftor.954651 removal tips

Malware Removal

The Graftor.954651 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.954651 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.954651?


File Info:

name: DFC6F507A351383BF450.mlw
path: /opt/CAPEv2/storage/binaries/9a8b6ceabde7a501d5a417469b9768b441c158aa1a1418483779bbd4c418b346
crc32: 3747CCF0
md5: dfc6f507a351383bf450a1ed51048da2
sha1: ea16269788d65105cc51f6221db74a356b6e8c69
sha256: 9a8b6ceabde7a501d5a417469b9768b441c158aa1a1418483779bbd4c418b346
sha512: 91f706aefc5b303fbd77a94a743cc076ff6939ca5a7588af52d302f715fcced9f1fbd7432306f9d083d3553607e84f0e02e35bbd68d585a833b655ad15230316
ssdeep: 3072:WSR8nKbjwQ26dbb6h54MpSrKb9oylCm/+ia8yzqbTuO:W4rjNxb6goKKbLlCm/Tkzqbi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CEC302B75D20FEABC294DFFA5E60D8E470672EC84675E181C86CBCF53412561DA8CC58
sha3_384: ef382b6bb562a58345e0e5b4249675e92746dc362f97463ad71e8fb3621c6a8280cfc6d5cd4d7cc4263c8609376f8081
ep_bytes: bb000000005029ff09fa425981ea41ce
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Graftor.954651 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Graftor.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.954651
McAfeeGenericRXAA-FA!DFC6F507A351
ZillyaTrojan.Copak.Win32.33231
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Injector.cd4ec068
K7GWTrojan ( 0058c5ff1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.DYV.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Copak
BitDefenderGen:Variant.Graftor.954651
NANO-AntivirusTrojan.Win32.TrjGen.iwtzch
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Agen.Pnkl
EmsisoftGen:Variant.Graftor.954651 (B)
F-SecureHeuristic.HEUR/AGEN.1333434
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Graftor.954651
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.dfc6f507a351383b
SophosMal/HckPk-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.954651
AviraHEUR/AGEN.1333434
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Graftor.DE911B
ZoneAlarmUDS:Trojan.Win32.Copak
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R415325
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36350.hmW@a40agRl
ALYacGen:Variant.Graftor.954651
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Graftor.954651?

Graftor.954651 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment