Malware

About “Graftor.981512” infection

Malware Removal

The Graftor.981512 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.981512 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Graftor.981512?


File Info:

name: 52BF9627DB700C8D607F.mlw
path: /opt/CAPEv2/storage/binaries/f89ab31ae1f7df62376ca3a492d8badf945dc15657971aba93f557d0bae25f64
crc32: 7804F1F6
md5: 52bf9627db700c8d607f164bd3e2ff97
sha1: 8647ddd9a6592af4f3aca83de3cac1b05ceff8f3
sha256: f89ab31ae1f7df62376ca3a492d8badf945dc15657971aba93f557d0bae25f64
sha512: 2ac8c6bd72f9d7518bd08ec9bd9677d6b7efe8527dfb1fe834f67d4db86201cbd8dcd7aedf85d685562c6d2c56c8645a3ea531eff041b027884ffb5c39567fef
ssdeep: 6144:u50gUCB9fdyZyyIf1uyPr9DTL8CDrpoLy:g0gnfdyZTg1JP1YCDrpoL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1265501037BD98C71E5ED0AB15DB5E5A2587AFD160830E73B53908E9E3E31892CE14B1E
sha3_384: ed013d71c652f3dcdcd899f838b5d34771c56eda8772429500839d09e22b93356a102b225e860466c194147545d9f927
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:20:04

Version Info:

FileDescription:
FileVersion: 1.0.0.0
LegalCopyright: lev
ProductVersion: 1.0.0.0
Translation: 0x0000 0x04b0

Graftor.981512 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.m!c
MicroWorld-eScanGen:Variant.Graftor.981512
FireEyeGeneric.mg.52bf9627db700c8d
ALYacGen:Variant.Graftor.981512
ZillyaDropper.Mine.Win32.155
K7AntiVirusTrojan ( 0054c4a01 )
AlibabaTrojan:Win32/Crypzip.7ce10b30
K7GWTrojan ( 0054c4a01 )
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Packed.Filerepmalware-9864117-0
KasperskyTrojan.Win32.Crypzip.bua
BitDefenderGen:Variant.Graftor.981512
SUPERAntiSpywareTrojan.Agent/Gen-Crypzip
AvastNSIS:MalwareX-gen [Trj]
RisingTrojan.HiddenRun/SFX!1.D57B (CLASSIC)
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
EmsisoftGen:Variant.Graftor.981512 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.981512
AviraTR/ClipBanker.ghwpe
MAXmalware (ai score=81)
ArcabitTrojan.Graftor.DEFA08
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4561194
McAfeeArtemis!52BF9627DB70
VBA32Backdoor.Agent
TrendMicro-HouseCallTROJ_GEN.R002H0DKO21
TencentWin32.Trojan-qqpass.Qqrob.Svrr
BitDefenderThetaGen:NN.ZexaF.34294.pr3@aWim4ijQ
AVGNSIS:MalwareX-gen [Trj]
PandaTrj/CI.A

How to remove Graftor.981512?

Graftor.981512 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment