Malware

What is “Application.Graftor.477019 (B)”?

Malware Removal

The Application.Graftor.477019 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.477019 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Graftor.477019 (B)?


File Info:

name: 9A8BBE26F0DEC060FCAF.mlw
path: /opt/CAPEv2/storage/binaries/33a93aa04409e43393dfc6f809f8f71f19b32909ed5fceb42aee4073586ed2d2
crc32: 87BD334C
md5: 9a8bbe26f0dec060fcaf56db41d13216
sha1: 6f3d7e02f99fa12204bcc808813e229f3f465285
sha256: 33a93aa04409e43393dfc6f809f8f71f19b32909ed5fceb42aee4073586ed2d2
sha512: 712f8e454a1650c22837cbfb98e81cd5e1d6463ebc5276b5b5728f880626cd7f3359fc479f0d58bc74a9bff7f11efef8ddf9deea0c2be1f16e349142651d6212
ssdeep: 24576:+ObJuwSkP5a4jESBK/gOypFLyRRP4xHYg5BHFTTai9ZXHAo2mm4:lbBBK/Jo9IP4x4g5BxuiLx2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9B5CFF9294A07BBAC2693FDB00A885E99CA2FE7650EA115DFF012E30F5D3151562D3C
sha3_384: 7887999eb3ae7f701395de680bcd9e068a77b59df7a35a75b18950c4d016143e349168c5e4d684c7aa38a4396230cb02
ep_bytes: 60be00509f008dbe00c0a0ff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Application.Graftor.477019 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Application.Graftor.477019
FireEyeGeneric.mg.9a8bbe26f0dec060
ALYacGen:Variant.Application.Graftor.477019
CylanceUnsafe
ZillyaTool.Patcher.Win32.22959
SangforTrojan.Win32.Generic.5
Cybereasonmalicious.6f0dec
CyrenW32/Trojan.JTDN-6023
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/HackTool.Patcher.EL potentially unsafe
APEXMalicious
AvastFileRepMalware
BitDefenderGen:Variant.Application.Graftor.477019
SophosGeneric PUA GP (PUA)
ComodoMalware@#1gh76ew5t7c3k
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEC-VJ!89EC1996B4BB
EmsisoftGen:Variant.Application.Graftor.477019 (B)
Paloaltogeneric.ml
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24FF065
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Application.Graftor.477019
CynetMalicious (score: 100)
McAfeeArtemis!9A8BBE26F0DE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bitrep
MalwarebytesMalware.AI.2513007861
TrendMicro-HouseCallTROJ_GEN.R002H06DJ21
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
YandexTrojan.GenAsa!SAaul19QblA
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Patcher
BitDefenderThetaGen:NN.ZelphiF.34182.ooGfaOO760
AVGFileRepMalware
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Application.Graftor.477019 (B)?

Application.Graftor.477019 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment