Malware

Application.Graftor.557793 removal instruction

Malware Removal

The Application.Graftor.557793 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.557793 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Graftor.557793?


File Info:

name: F818278010ED8D82E86F.mlw
path: /opt/CAPEv2/storage/binaries/8a6d1f85e7ab08af00116def145ad1c74841cbd114a2d566207495974b4b9205
crc32: 8026D9D3
md5: f818278010ed8d82e86f4e33501d05cc
sha1: de36dc5f5252cc129e606d6bd28454ca8a1eaef5
sha256: 8a6d1f85e7ab08af00116def145ad1c74841cbd114a2d566207495974b4b9205
sha512: f2c17b1dd40bcd878e50a5ef62d44fb4d6099cf3a8bbfa2a6263140beb491eb68257108ade0678cc701c8663240dae793248dcf7f6212c4627bbe76d7297282f
ssdeep: 24576:CBd3X3BBt4vid+ESX786/e6ksNW12oRY6unCVIXZv/U:CBdH3BBL3SQ6/e6rNnoRYTn1XZv/U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F055339E5E227BFBDA1E2D73F4A48730D078AB52BF7F810DA87C24332AA1354550D865
sha3_384: 31f2195c4dc35ec7fe03c5c0106c70ae7b8e50dc1c89b4d045b1088edc712844361ec944872485070f3e56c17720e812
ep_bytes: eb0800b204000000000060e800000000
timestamp: 2010-12-09 18:58:13

Version Info:

0: [No Data]

Application.Graftor.557793 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Graftor.557793
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXMR-KT!4FC8E579FC1E
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Application.Graftor.557793
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Application.Graftor.557793 (B)
F-SecureHeuristic.HEUR/AGEN.1314173
VIPREGen:Variant.Application.Graftor.557793
SophosGeneric ML PUA (PUA)
IkarusTrojan.Dropper.Agent
VaristW32/Virut.AI!Generic
AviraHEUR/AGEN.1314173
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Application.Graftor.D882E1
GDataWin32.Trojan.PSE.1L0J4MO
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R575148
BitDefenderThetaGen:NN.ZexaF.36680.ozW@a4uI1Xp
ALYacGen:Variant.Application.Graftor.557793
VBA32Trojan.Wacatac
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Application.Graftor.557793?

Application.Graftor.557793 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment