Malware

Graftor.48516 information

Malware Removal

The Graftor.48516 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.48516 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.48516?


File Info:

name: EE19C0C26937B53954ED.mlw
path: /opt/CAPEv2/storage/binaries/11c760caba9dfb4a651db10180a688febcb8f0dbbf0a2af2643c4a3419614535
crc32: 272B4039
md5: ee19c0c26937b53954ed6d8052933187
sha1: 0adb28d78ccc6c3f0bafe4ab9b11e2cf6ebdfcaf
sha256: 11c760caba9dfb4a651db10180a688febcb8f0dbbf0a2af2643c4a3419614535
sha512: 48cf1b013e93a9b6ccf02469fa385c3ac1995ceb4a9a25dd414fca559dd972b4196fc3dc7d010688c4933f3348542b7a8c0e60a70a74aade0b3825728ba00d45
ssdeep: 12288:0HmcoCUy4twAvAs4wTCyrPTdiQzvGErkPDloJpaz/g/J/vIS:umftywwAvN7lrhRkPDKaz/g/J/g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE2507419692DD65EF101438040F3BF897E17EAC8B06E6BB9110FE1E9DB5283B1AD7C6
sha3_384: 88c8b253be07c1f277dd37f6405b40e382d138c8a0248e59ebcf83ae409c8546ce622d0dd51ff10620355a16d90794d3
ep_bytes: 60e80e0000008920e88f020000e8b200
timestamp: 2008-04-13 19:17:04

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Проводник
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: explorer
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: EXPLORER.EXE
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 6.00.2900.5512
Translation: 0x0419 0x04b0

Graftor.48516 also known as:

MicroWorld-eScanGen:Variant.Graftor.48516
FireEyeGeneric.mg.ee19c0c26937b539
ALYacGen:Variant.Graftor.48516
CylanceUnsafe
VIPREGen:Variant.Graftor.48516
SangforTrojan.Win32.Save.a
Cybereasonmalicious.26937b
Elasticmalicious (high confidence)
ESET-NOD32Win32/Leprum.A
APEXMalicious
ClamAVWin.Trojan.Agent-1120371
KasperskyVirus.Win32.Lamer.dl
BitDefenderGen:Variant.Graftor.48516
NANO-AntivirusVirus.Win32.Lamer.vpqnt
AvastWin32:RuSpy [Inf]
Ad-AwareGen:Variant.Graftor.48516
EmsisoftGen:Variant.Graftor.48516 (B)
ComodoVirus.Win32.Leprum.A@4sjfa7
DrWebWin32.Leprum.1
McAfee-GW-EditionArtemis!Virus
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.48516
JiangminTrojan/Inject.yej
GoogleDetected
AviraTR/Patched.Gen
MAXmalware (ai score=84)
ArcabitTrojan.Graftor.DBD84
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeGeneric Obfuscated.g
VBA32Virus.Lamer.D1
RisingMalware.Undefined!8.C (TFE:2:nkTOLVCtc9I)
IkarusVirus.Win32.Virut
MaxSecureVirus.W32.Lamer.DL
FortinetW32/Menti.JE!tr
BitDefenderThetaGen:NN.ZexaF.34646.@q0@aS@JFtjc
AVGWin32:RuSpy [Inf]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.48516?

Graftor.48516 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment