Malware

What is “Graftor.382845”?

Malware Removal

The Graftor.382845 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.382845 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Graftor.382845?


File Info:

name: B0B9A8EE63A906675762.mlw
path: /opt/CAPEv2/storage/binaries/01ba48461b312313466431853f2f80bac96d8344836ebf60054a93e02adac8a7
crc32: 139BB8DE
md5: b0b9a8ee63a906675762014a591a546b
sha1: 1d82de55e381d3199e635d73badde2a87603cc0e
sha256: 01ba48461b312313466431853f2f80bac96d8344836ebf60054a93e02adac8a7
sha512: 750e3599d37f1eb2c2d3cde28177cd4578e38d068845cd8e48641ac71d9e6d1e095e35b3ccb0e4faede492928832b9c60ebc354e2e763b3c337704c5c1ca3d04
ssdeep: 49152:yh+IK8vGga2oxMR9PoVz7lj4CQntqHljelaIYBkDtCn:yEIi2oxMGlE5tceQCo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199A52211B2D180BAEAA255310DE85B7BB7B9BD204F218FC363C4FF1DB9724D25622716
sha3_384: bd64accae9dcea2612f59f55da4eac562cf0af97541809801d70a8a4cbf980eb24567bdc96fbf22f98981f98eabdb221
ep_bytes: 558bec6aff68902c430068c4be410064
timestamp: 2008-10-28 13:09:46

Version Info:

Comments: Created with AutoPlay Media Studio
CompanyName:
FileDescription: AutoPlay Application
FileVersion: 7.5.1004.0
InternalName: ams_launch
LegalCopyright: Runtime Engine Copyright © 2008 Indigo Rose Corporation (www.indigorose.com)
LegalTrademarks: AutoPlay Media Studio is a Trademark of Indigo Rose Corporation
OriginalFilename: ams_launch.exe
PrivateBuild:
ProductName: AutoPlay Media Studio Launcher
ProductVersion: 7.5.1004.0
SpecialBuild:
Translation: 0x0409 0x04b0

Graftor.382845 also known as:

LionicTrojan.Win32.Banbra.7!c
MicroWorld-eScanGen:Variant.Graftor.382845
FireEyeGeneric.mg.b0b9a8ee63a90667
McAfeeW32/Worm-GAO!B0B9A8EE63A9
CylanceUnsafe
SangforTrojan.Win32.Banbra.gen
K7AntiVirusTrojan ( 004de8381 )
AlibabaTrojanBanker:Win32/Banbra.56f57814
K7GWTrojan ( 004de8381 )
CrowdStrikewin/malicious_confidence_70% (W)
VirITTrojan.Win32.AutoPlay.A
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoPlayStudio.A
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cazu-9847849-0
KasperskyHEUR:Trojan-Banker.Win32.Banbra.gen
BitDefenderGen:Variant.Graftor.382845
TencentWin32.Trojan-banker.Banbra.Pepl
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PB322
EmsisoftGen:Variant.Graftor.382845 (B)
AviraTR/Banbra.vezfw
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftWorm:Win32/Aicat.A!ml
ZoneAlarmHEUR:Trojan-Banker.Win32.Banbra.gen
GDataGen:Variant.Graftor.382845
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34182.cs3@aawUQihi
ALYacGen:Variant.Graftor.382845
MAXmalware (ai score=89)
MalwarebytesMalware.AI.213340896
TrendMicro-HouseCallTROJ_GEN.R002C0PB322
RisingTrojan.Generic@AI.98 (RDMK:tXLuNiYXXZ58GK/KYMBeKg)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.11586831.susgen
FortinetW32/AutoPlayStudio.A!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e63a90
PandaTrj/CI.A

How to remove Graftor.382845?

Graftor.382845 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment