Malware

How to remove “Application.Graftor.750661 (B)”?

Malware Removal

The Application.Graftor.750661 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.750661 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Application.Graftor.750661 (B)?


File Info:

name: 146BE8E318FCEA33D5B9.mlw
path: /opt/CAPEv2/storage/binaries/8a665a072388bb522513a70adf0ea8ac6c10fe15b67f6db4ba3202e40e1c3eb5
crc32: 346016BD
md5: 146be8e318fcea33d5b9b8b8904b3f74
sha1: 9f759b9f67af1265c861f1d2ef050113b91f6f9b
sha256: 8a665a072388bb522513a70adf0ea8ac6c10fe15b67f6db4ba3202e40e1c3eb5
sha512: d861cef5ee71f47024c139feb70183d9688d55979086b47955a663b2dde55362b05e0a56c55ab3774346e63b00479a0c513617a58cc5731075039430c9ef5d2c
ssdeep: 98304:/AQWSHU+DTwl9zOHz7t1Q5RRlWY9HJ3CChZfYQmGYtYE+FUQdpa1:YQWQU4TIqY5BZdwnGga2wk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B166338A8A2B3279C548163D944F0B2BE311CF990E78625343D0369F34A796FDF17A97
sha3_384: 8f3108b1a99a6c7ef94e5320c96bf8e1eca7d4ebebbfdd89c95b9b01fa7164b1367840b7d8a15275f971fc2b266dd274
ep_bytes: 6801b02b32e801000000c3c3498db9f3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Application.Graftor.750661 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Graftor.750661
ClamAVWin.Malware.Generic-9954271-0
FireEyeGeneric.mg.146be8e318fcea33
McAfeeGenericRXAA-AA!146BE8E318FC
CylanceUnsafe
VIPREGen:Variant.Application.Graftor.750661
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005436321 )
BitDefenderGen:Variant.Application.Graftor.750661
K7GWTrojan ( 005436321 )
Cybereasonmalicious.318fce
ArcabitTrojan.Application.Graftor.DB7445
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.HX
APEXMalicious
CynetMalicious (score: 100)
Ad-AwareGen:Variant.Application.Graftor.750661
SophosGeneric ML PUA (PUA)
ZillyaTrojan.Asprotect.Win32.3
McAfee-GW-EditionBehavesLike.Win32.InstallMonster.vc
EmsisoftGen:Variant.Application.Graftor.750661 (B)
IkarusTrojan.Win32.ASProtect
AviraHEUR/AGEN.1212664
MAXmalware (ai score=78)
Antiy-AVLTrojan/Generic.ASMalwS.542C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Application.Graftor.750661
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R512323
BitDefenderThetaGen:NN.ZexaF.34646.@RZaaCsqDjob
ALYacGen:Variant.Application.Graftor.750661
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.4273929312
YandexTrojan.GenAsa!XHPWPUxbPWE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Application.Graftor.750661 (B)?

Application.Graftor.750661 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment