Malware

Application.Graftor.858453 information

Malware Removal

The Application.Graftor.858453 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.858453 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk

How to determine Application.Graftor.858453?


File Info:

name: CA3FF6C78737452865CB.mlw
path: /opt/CAPEv2/storage/binaries/57a5487a4a3793683f859955b8c7a8227416ef6ee054ba2d59638ba50bc39342
crc32: 54F16051
md5: ca3ff6c78737452865cb2fcf21eaeacb
sha1: e14aede902cd353b5cdfb2c70646db33e5199dc3
sha256: 57a5487a4a3793683f859955b8c7a8227416ef6ee054ba2d59638ba50bc39342
sha512: 0da83908393903cb1a4516178eef103805aaef5b366ab646f7bb93d64370712c98f00459f1c0c38e4d48573ed302934d32e975d8103105da20d3ddefa93dcff0
ssdeep: 24576:7JRXQlFED4/MKxOYVWOJUcxU5puaQZtJVoIJLV:7uEiWOJe8aQHJL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF45336715D00AB5FC3B20BC18F781FAA678984C3A7E02AD8345712EDD5789AB790737
sha3_384: b6dfcdf85394d0401b83845f011c5ccd743e98582a1ddb7e6aa1c220b1804722d0c50dd1eb77a7cede166e98c5eea37c
ep_bytes: 60be006046008dbe00b0f9ff57eb0b90
timestamp: 2020-04-20 08:27:23

Version Info:

CompanyName: NirSoft
FileDescription: WifiInfoView
FileVersion: 2.72
InternalName: WifiInfoView
LegalCopyright: Copyright © 2012 - 2021 Nir Sofer
OriginalFilename: WifiInfoView.exe
ProductName: WifiInfoView
ProductVersion: 2.72
Translation: 0x0409 0x04b0

Application.Graftor.858453 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Graftor.858453
FireEyeGeneric.mg.ca3ff6c787374528
ALYacGen:Variant.Application.Graftor.858453
CylanceUnsafe
VIPREGen:Variant.Application.Graftor.858453
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005071f51 )
K7GWAdware ( 005071f51 )
Cybereasonmalicious.787374
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
BitDefenderGen:Variant.Application.Graftor.858453
Ad-AwareGen:Variant.Application.Graftor.858453
EmsisoftGen:Variant.Application.Graftor.858453 (B)
ZillyaTool.KMSAuto.Win32.1750
McAfee-GW-EditionGenericRXMK-BN!B0FA470F1CCE
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.Upatre
GDataGen:Variant.Application.Graftor.858453
JiangminTrojan.Agent.cocc
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=75)
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitTrojan.Application.Graftor.DD1955
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXMK-BN!B0FA470F1CCE
VBA32BScope.Trojan.Witch
MalwarebytesMalware.AI.602160975
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34606.nnNfa4Xhy6aH
PandaTrj/Genetic.gen

How to remove Application.Graftor.858453?

Application.Graftor.858453 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment