Malware

About “Graftor.968177 (B)” infection

Malware Removal

The Graftor.968177 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.968177 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.968177 (B)?


File Info:

name: 5EB206A779E475CAB154.mlw
path: /opt/CAPEv2/storage/binaries/c681afb9bbe0f4260a92dfba64b20f255ed93426d5ea4a12c4a31088087bc06a
crc32: 399D7627
md5: 5eb206a779e475cab154952409531d82
sha1: 8b2afd1435b00981245a0a6a8f1d7775c9be23d0
sha256: c681afb9bbe0f4260a92dfba64b20f255ed93426d5ea4a12c4a31088087bc06a
sha512: 8f6d3f56445ac315ec6676f3b25669ab987f78b02d1775da42a5bc0b9386205486fb1c930840c76a096e142396cd792d7aad3cff4548500d842aed13abf993f0
ssdeep: 768:/LLZHhumMkC3lRUKIwX0GDXGcADvGVsh+7yCbTKhmN1uyK:/nZHdjUlGGDXjm07OeK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADD21A12FB99B4E3D9D246F0230A130573222E3125A42C9B8D55EE6F59753B3AF9432F
sha3_384: 87245a2e41308ceabfa5aac3ac4cbc7cfda6096ebcc15c3c9e17f3211023deb5b422511d39bc1f113dc8b0eb82e36c80
ep_bytes: 68e0244000e8eeffffff000000000000
timestamp: 2007-08-17 12:43:04

Version Info:

0: [No Data]

Graftor.968177 (B) also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.AutoRun.trSR
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.968177
FireEyeGeneric.mg.5eb206a779e475ca
CAT-QuickHealTrojan.Sabsik
ALYacGen:Variant.Graftor.968177
CylanceUnsafe
AlibabaVirus:Win32/Autorun.932489b6
Cybereasonmalicious.779e47
CyrenW32/Damaged_File.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Graftor.968177
NANO-AntivirusTrojan.Win32.AutoRun.bqzoew
RisingTrojan.Generic@ML.93 (RDML:mkzmjSZhpEVr59U3zXc+aw)
Ad-AwareGen:Variant.Graftor.968177
SophosMal/Generic-S
DrWebWin32.HLLW.Autoruner.547
TrendMicroTROJ_GEN.R03FC0PKP21
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
EmsisoftGen:Variant.Graftor.968177 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.968177
JiangminWorm.AutoRun.ys
Antiy-AVLTrojan/Generic.ASMalwS.31F988D
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Graftor.DEC5F1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=89)
MalwarebytesMalware.AI.2797890020
TrendMicro-HouseCallTROJ_GEN.R03FC0PKP21
YandexTrojan.Agent!rQ/48ROHkTg
FortinetW32/VB.FBX
BitDefenderThetaGen:NN.ZevbaF.34294.buW@amEz5Pj
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Graftor.968177 (B)?

Graftor.968177 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment