Malware

What is “Graftor.385372”?

Malware Removal

The Graftor.385372 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.385372 virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.385372?


File Info:

name: 6C663D1A312C2CE07D8F.mlw
path: /opt/CAPEv2/storage/binaries/ef48b00341ce4047b328992be2f265f4fe55eacc597d0abbca0273971b283c3e
crc32: C6F83EAA
md5: 6c663d1a312c2ce07d8f9b53c0b6985e
sha1: 07792fd8ff7cc3d0bf7220cef2e619306fa9057f
sha256: ef48b00341ce4047b328992be2f265f4fe55eacc597d0abbca0273971b283c3e
sha512: 6f62256990a36a4dc7c83e42922068e13bc81d7a850942b8a9447eaf6741a0caab963325f77ecc8709b9e12209ccde711d3b9ab3e2858801957c527f81d864a2
ssdeep: 3072:jImwL8huLUbWjxOoGf6ZsSW/Q4C/P7f3gEzOcuosuXgvjmWk3Kw1ES:g8huLEWFCoPSREc48S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7643EF1A0A043E7C39EDDF01BD9B7808A1F9AF736340162A54C22ED66EC49C56DF616
sha3_384: 8917d7f1fbda32435e0a8d8db1b64b0b4e3b4eb20d3bf40235e885554fe84e598ed5e2a0488a50ed87a1ddfed03c4044
ep_bytes: e845050000e980feffff558becff7508
timestamp: 2017-06-23 01:28:54

Version Info:

CompanyName: Download Version
FileDescription: Download Version
FileVersion: 14.42.43.45
InternalName: Download Version
LegalCopyright: Download Version
LegalTrademarks: Download Version
OriginalFilename: Download Version
ProductName: Download Version
ProductVersion: 5.5.5.6
Translation: 0x0000 0x04e4

Graftor.385372 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6c663d1a312c2ce0
CAT-QuickHealAdware.Dataric.A5
McAfeeGenericRXBW-AP!6C663D1A312C
CylanceUnsafe
VIPREGen:Variant.Graftor.385372
K7AntiVirusTrojan-Downloader ( 005108891 )
BitDefenderGen:Variant.Graftor.385372
K7GWTrojan-Downloader ( 005108891 )
Cybereasonmalicious.a312c2
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.AU
APEXMalicious
ClamAVWin.Dropper.Tovkater-6683743-0
Kasperskynot-a-virus:VHO:AdWare.Win32.TOVus.gen
NANO-AntivirusRiskware.Win32.TOVus.eqhuhc
MicroWorld-eScanGen:Variant.Graftor.385372
TencentMalware.Win32.Gencirc.10b3f8c6
Ad-AwareGen:Variant.Graftor.385372
EmsisoftGen:Variant.Graftor.385372 (B)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.G@72ttyk
DrWebTrojan.InstallMonster.2420
McAfee-GW-EditionBehavesLike.Win32.Emotet.fm
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.385372
JiangminTrojanDownloader.Generic.awiw
AviraHEUR/AGEN.1228743
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Graftor.D5E15C
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
AhnLab-V3PUP/Win32.InstallMonster.R203296
Acronissuspicious
VBA32AdWare.TOVus
ALYacGen:Variant.Graftor.385372
MAXmalware (ai score=85)
MalwarebytesInstallMonster.Adware.Bundler.DDS
RisingDownloader.Tovkater!1.ABF6 (CLASSIC)
IkarusTrojan-Downloader.Win32.Tovkater
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.F4BA0!tr
BitDefenderThetaGen:NN.ZexaF.34786.ty2@ayeLMilI

How to remove Graftor.385372?

Graftor.385372 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment