Malware

What is “Graftor.478285”?

Malware Removal

The Graftor.478285 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.478285 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects VirtualBox through the presence of a device
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Graftor.478285?


File Info:

name: B1E909D3FCDAD9564043.mlw
path: /opt/CAPEv2/storage/binaries/85c3ff7c972b6315fd49e17bcafed4c453b69de1f2c1e6df0f528233b42b1ca1
crc32: E69F25AC
md5: b1e909d3fcdad9564043fc96cd3df1f5
sha1: b34102322825e087442d992b1003bceca839968f
sha256: 85c3ff7c972b6315fd49e17bcafed4c453b69de1f2c1e6df0f528233b42b1ca1
sha512: edd93c5502a1628ecba4be310b3468bf9c364398d779f7584f9fef6fd78eef1432c986997141b0da21978074a76db2ebc2c477dddce1d70c49dba1f16f5c9129
ssdeep: 768:H3tWGTJB2XSbjkWB0+Fo41o/ZuWGlA3sTOw0B1G:H3tWGTXP/Fot/ZuWGLTOwqG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1AEF2D649674ED0B2CDAE56740CD0090A87F5BC4D1BF45EE397B3EDAA09A73E42872123
sha3_384: df1be79e00afb87aba2b52117ef4fe9ce292375451aaa7afca0c2ccf3e012be29a6ece00f78d7a742f7f4a1595e844c9
ep_bytes: 8b442404a36ca40010b801000000c20c
timestamp: 2017-11-30 10:01:06

Version Info:

0: [No Data]

Graftor.478285 also known as:

BkavW32.Common.1C52FB16
LionicAdware.Win32.Agent.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.478285
FireEyeGeneric.mg.b1e909d3fcdad956
SkyhighGenericRXDW-NP!B1E909D3FCDA
McAfeeGenericRXDW-NP!B1E909D3FCDA
MalwarebytesAdware.SpecialSearchOffer
ZillyaAdware.OpenSUpdater.Win32.2208
SangforAdware.Win32.Opensupdater.V3cc
CrowdStrikewin/grayware_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.OpenSUpdater.AZ
CynetMalicious (score: 100)
Kasperskynot-a-virus:VHO:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Graftor.478285
NANO-AntivirusRiskware.Win32.OpenSUpdater.exwplh
AvastFileRepMalware [Trj]
TencentMalware.Win32.Gencirc.10b471db
SophosGeneric Reputation PUA (PUA)
DrWebAdware.Downware.18667
VIPREGen:Variant.Graftor.478285
TrendMicroTROJ_GEN.R002C0PBL24
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Graftor.478285 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Graftor.478285
JiangminAdware.Agent.ajkd
Antiy-AVLGrayWare[AdWare]/Win32.Agent
Kingsoftmalware.kb.a.978
XcitiumApplicUnwnt@#7e7dq4od9uar
ArcabitTrojan.Graftor.D74C4D
ZoneAlarmnot-a-virus:VHO:AdWare.Win32.Agent.gen
ALYacGen:Variant.Graftor.478285
MAXmalware (ai score=81)
VBA32Adware.Downware
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PBL24
RisingTrojan.Generic@AI.87 (RDML:bwmh4sximfbLPafLc4tkAw)
YandexTrojan.GenAsa!s4rM5N25b3s
IkarusPUA.OpenSUpdater
MaxSecureTrojan.Malware.73852572.susgen
FortinetRiskware/OpenSUpdater
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS

How to remove Graftor.478285?

Graftor.478285 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment