Malware

Application.Graftor.372788 (file analysis)

Malware Removal

The Application.Graftor.372788 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.372788 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Application.Graftor.372788?


File Info:

name: 8631D96B4B1D848BA580.mlw
path: /opt/CAPEv2/storage/binaries/c9fd4de218f0a484c4d5fecdc46204c160345bbd46fc113dbff631f54daeed88
crc32: A9FE8A9E
md5: 8631d96b4b1d848ba5805f3dc2833683
sha1: 089569291b75ea579ff0f83912407526284c4dad
sha256: c9fd4de218f0a484c4d5fecdc46204c160345bbd46fc113dbff631f54daeed88
sha512: 2e0f7a51e7eaf616a06cd186416cb8620736562a46484fe592b5a2851e9e0cefbeca00f4ee3f76eb613b3a9afc448d1a53da39a993025a10ddf41fc032eda83b
ssdeep: 98304:v+rGNHBJAx0lAnIWUofMQycAOUt4ae1ItuLY:p66vR47EGY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AE5D003E251C0B2E02416B425FA233A7D3C57A61E718ED3E7D4DDB46E722A1976770E
sha3_384: 380a2233b6f3560667a924d17ad02450ea68259711d22ff50da6e954f765a2189f2ce7368b965f75a327a89bf5a00e8a
ep_bytes: 558bec6aff68389f6e0068cc3d4d0064
timestamp: 2022-03-17 11:12:03

Version Info:

FileVersion: 6.7.0.9
FileDescription: ★回//忆★
ProductName: ★回//忆★
ProductVersion: 6.7.0.9
CompanyName: ★回//忆★
LegalCopyright: ★回//忆★
Comments: ★回//忆★
Translation: 0x0804 0x04b0

Application.Graftor.372788 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Graftor.372788
FireEyeGeneric.mg.8631d96b4b1d848b
CAT-QuickHealRisktool.Flystudio.16882
ALYacGen:Variant.Application.Graftor.372788
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Application.Graftor.372788
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.b4b1d8
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Flystudio-9752414-0
RisingTrojan.Generic@AI.99 (RDMK:cmRtazrSv1cco/DkgMEnYXEYc9WI)
Ad-AwareGen:Variant.Application.Graftor.372788
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Application.Graftor.372788 (B)
IkarusTrojan-Downloader
AviraTR/Spy.Gen
MAXmalware (ai score=76)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1CJLVYA
CynetMalicious (score: 100)
VBA32BScope.DDoS.Npf
MalwarebytesTrojan.MalPack.FlyStudio
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Application.Graftor.372788?

Application.Graftor.372788 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment