Malware

Graftor.972592 (B) removal

Malware Removal

The Graftor.972592 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.972592 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Graftor.972592 (B)?


File Info:

name: FB8B3757CFE8DEF7D437.mlw
path: /opt/CAPEv2/storage/binaries/71f71a1d5bb675fc12155fa9b3dcbb641321e495d9d5ffcad9fb0acdfdaf0f50
crc32: 0A715DC0
md5: fb8b3757cfe8def7d43732e9cd575e54
sha1: 8fb5dd4b092abf445a362c3cb49927f7531d18b8
sha256: 71f71a1d5bb675fc12155fa9b3dcbb641321e495d9d5ffcad9fb0acdfdaf0f50
sha512: 530c65f6912b1a30a69b3d02dac9e0c33d40c61e73cf0022398576081129313097d00871047c2dac4c1723095c68cfdcbd7b0c7b1880513a278a491a565cb86f
ssdeep: 49152:hHEZYG+xcVBZQO3/K9TqLeWlt49ZA893xuiR/CuEZd1rYwrFvSRo6km2z2FRzb:hHHvcVBpPSSxlt6MiR/mt7qRo6h2zQd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B3E533341302E8F3CE562F7E77AB6405A06A320A18375F6E69350E5BB58F8D2D616C3D
sha3_384: 5b1ad4b76f34039789f28400248e3d885575d566c194e5c3727ae635f4d635eabd10812f6747abcc9977f98b33e0cf44
ep_bytes: ba000000005609df5881efe46f095dbf
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Graftor.972592 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Graftor.972592
FireEyeGen:Variant.Graftor.972592
McAfeeGenericRXAA-AA!FB8B3757CFE8
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Injector.2337733e
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.b092ab
BitDefenderThetaGen:NN.ZexaF.34182.XmW@amPuiRk
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB522
AvastWin32:CoinminerX-gen [Trj]
KasperskyTrojan.Win32.Copak.qdgx
BitDefenderGen:Variant.Graftor.972592
TencentTrojan.Win32.Coinminer.yi
EmsisoftGen:Variant.Graftor.972592 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-R
Paloaltogeneric.ml
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C687
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ZoneAlarmTrojan.Win32.Copak.qdgx
GDataGen:Variant.Fragtor.19825 (2x)
AhnLab-V3Malware/Win32.Generic.R371287
VBA32Trojan.Packed
MAXmalware (ai score=80)
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Injector!bgxet+w3A9k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Graftor.972592 (B)?

Graftor.972592 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment