Malware

Application.Graftor.488675 removal instruction

Malware Removal

The Application.Graftor.488675 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.488675 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Graftor.488675?


File Info:

name: 7C459B7A63C6A338F369.mlw
path: /opt/CAPEv2/storage/binaries/ff13cea0815b37911caf5f30f08fc88ea25c8722046486c6752fe8c955ded1c6
crc32: C2C8BF3E
md5: 7c459b7a63c6a338f369dcfb462ed7af
sha1: 4084de1ac4d54e4144b48e6795c2e31efd016856
sha256: ff13cea0815b37911caf5f30f08fc88ea25c8722046486c6752fe8c955ded1c6
sha512: 86ebad6605981310f79bb05499d71a76376b35f5dc080dde42187a78f08b0479072e0a686d382cdd7db4b302fdbd97a64c42332ceb3e82e3713d587d724f9a44
ssdeep: 6144:Tv9p8uiFHOp0L/N6T1yijDTfZXskiOVPYHtcA/+t5T5JN/PKwKdnbGh61KpJFPWF:rz6ZLN6T1ycHxfOKEod5JNqXdC5Jx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122D49F02F9E3A0F5DA3556B0086A2736AA364E050F1DCFC7A364ED6EDD33D419937226
sha3_384: 009f7bf51031f327bdabf44194d3bb5cf379759f11404fdd5157e2c95d14eb5c2a034ea8ef3a202ac5cebb07c772d18b
ep_bytes: 558bec6aff68a827470068680a450064
timestamp: 2015-01-18 08:47:20

Version Info:

FileVersion: 1.0.0.0
FileDescription: 新浪微博:w0ai1uo
ProductName: 新浪微博:w0ai1uo
ProductVersion: 1.0.0.0
CompanyName: 新浪微博:w0ai1uo
LegalCopyright: 新浪微博:w0ai1uo
Comments: 新浪微博:w0ai1uo
Translation: 0x0804 0x04b0

Application.Graftor.488675 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Graftor.488675
ClamAVWin.Trojan.Agent-1361120
FireEyeGeneric.mg.7c459b7a63c6a338
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Application.Graftor.488675
Cylanceunsafe
ZillyaTrojan.QQPass.Win32.24392
SangforRiskware.Win32.Agent.ky
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a63c6a
ArcabitTrojan.Application.Graftor.D774E3
BitDefenderThetaGen:NN.ZexaF.36348.Oq0@aqofY0bb
VirITTrojan.Win32.DownLoader12.CNGY
CyrenW32/Trojan.ISO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/QQWare.AA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.QQPass.gen
BitDefenderGen:Variant.Application.Graftor.488675
NANO-AntivirusTrojan.Win32.QQPass.dnovzc
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b32471
TACHYONTrojan-PWS/W32.QQPass.655360.O
EmsisoftGen:Variant.Application.Graftor.488675 (B)
F-SecureTrojan:W32/DelfInject.R
DrWebTrojan.DownLoader13.22407
VIPREGen:Variant.Application.Graftor.488675
TrendMicroTROJ_QQWARE_EK0201AA.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.ScreenLocker
JiangminTrojan/PSW.QQPass.quv
WebrootW32.QQPass.cocl
AviraTR/Golroted.aqiqy
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmHEUR:Trojan-PSW.Win32.QQPass.gen
GDataWin32.Application.PSE.18M7LFX
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C820083
McAfeeGenericRXAA-AA!7C459B7A63C6
MAXmalware (ai score=75)
VBA32TrojanPSW.QQPass
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_QQWARE_EK0201AA.UVPM
RisingTrojan.Generic@AI.98 (RDML:x3CsD40o6IGpVRmF1XU4Yw)
YandexTrojan.GenAsa!EPeHg3bGut0
SentinelOneStatic AI – Malicious PE
FortinetAdware/GameCheater
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Graftor.488675?

Application.Graftor.488675 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment