Malware

About “Application.Graftor.596183” infection

Malware Removal

The Application.Graftor.596183 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.596183 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Application.Graftor.596183?


File Info:

name: 83AC431DA3EF5B2C4376.mlw
path: /opt/CAPEv2/storage/binaries/d213e8da1e5617dc73ceca29280d2c2a7965a0fee87fc6567946834e1c2b5fbe
crc32: 1E280B63
md5: 83ac431da3ef5b2c4376821a69e720a1
sha1: 3ce48185e708f057e1e8b5775066fb21d407ac32
sha256: d213e8da1e5617dc73ceca29280d2c2a7965a0fee87fc6567946834e1c2b5fbe
sha512: d47a5ee3fff738844ebc40f25792a5dd14b7f8fe80214f8ef89606ed569e1a213e1e8be88146e411736e89732f167cf8ad07ae7a047c06622d31061ea5c3cc49
ssdeep: 12288:X4+GOx+3xSFagaliNoxhm8/MED7Woa0S:XiOxhFMlmobm8/ME3Woa0S
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T107F4AE03B5A1C0F9E64C0571146A7F39DA7C9A064A2ECFCBE358EF795C32152D63B12A
sha3_384: f8835478d53b442eff5e8328687aa50184f3626c96f095f76211047da99a369507b864863a683e08f7d90c873d1a9045
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2012-03-29 09:25:56

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Application.Graftor.596183 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwgJ
MicroWorld-eScanGen:Variant.Application.Graftor.596183
FireEyeGeneric.mg.83ac431da3ef5b2c
SkyhighBehavesLike.Win32.Generic.bh
McAfeeGeneric.gn
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/QQTen.6c1f5527
BitDefenderThetaGen:NN.ZedlaF.36744.Su8@aKZQqTgb
SymantecML.Attribute.HighConfidence
ElasticWindows.Generic.Threat
ESET-NOD32a variant of Win32/PSW.QQTen.NAN
ClamAVWin.Dropper.Detected-10008752-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Graftor.596183
NANO-AntivirusRiskware.Win32.Cinmus.cudvet
AvastWin32:Malware-gen
EmsisoftGen:Variant.Application.Graftor.596183 (B)
F-SecureTrojan:W32/DelfInject.Q
VIPREGen:Variant.Application.Graftor.596183
SophosMal/Generic-S
IkarusTrojan-PSW.QQTen
GDataWin32.Trojan.FlyStudio.I
JiangminBackdoor/Hupigon.bziq
GoogleDetected
AviraTR/PSW.QQTen.xupbk
VaristW32/Trojan.GRW.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Application.Graftor.D918D7
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R603455
VBA32HackTool.Sniffer.WpePro
ALYacGen:Variant.Application.Graftor.596183
MAXmalware (ai score=76)
Cylanceunsafe
RisingStealer.QQTen!8.14F (TFE:5:YQ5Alwd5V3C)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetPossibleThreat.FORTIEDR.H
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Application.Graftor.596183?

Application.Graftor.596183 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment