Malware

How to remove “Graftor.497538”?

Malware Removal

The Graftor.497538 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.497538 virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Graftor.497538?


File Info:

name: B48B2A06C5BDA9438A7F.mlw
path: /opt/CAPEv2/storage/binaries/6f42a255739437b408724edfed1914a01623c946ee772d2d0265a83fbd0b1b06
crc32: A4E6DA0B
md5: b48b2a06c5bda9438a7f407ea52e5b7a
sha1: 9d4e993515c89f226793222377a2ff8a9cc7ae7b
sha256: 6f42a255739437b408724edfed1914a01623c946ee772d2d0265a83fbd0b1b06
sha512: 0c9f9502e09da78ebfad1f7732de51a06e0446a429ff01f471b88a0bc5dff2abf7dcbc3270d203e93961a46407395fa37a31ea4f2b849adedf66c22b3deb00e7
ssdeep: 98304:cQfPem1Vf+o1y5xWVLD1F2HxyAyX9YKpCYo0wpvkw7heNANsN/rE8Tgg1aBB3Hfn:ffmm1t+oU5xYLDGyX9NpLo7p7heeON/o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F346126313740149E0CECD399937BDF432F2177A6B41A8BD65FBE8C2E922496B253943
sha3_384: b5bac6d8e083a9f7b365fbba8b6a3ee2796be0a3a5a4bb7f75c1f954785b2bd8df5ae30c8f75e9af36c441e87e7664fe
ep_bytes: 558bec81ec1402000068dc7c4300ff15
timestamp: 2013-08-20 04:52:20

Version Info:

CompanyName: Корпорация М айкрософт
FileDescription: Диспетчер синхронизации
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
Translation: 0x0419 0x04b0

Graftor.497538 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Mods.1
MicroWorld-eScanGen:Variant.Graftor.497538
ALYacGen:Variant.Graftor.497538
MalwarebytesMalware.AI.3504209162
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040fa341 )
K7GWTrojan ( 0040fa341 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36196.@J0@ayHge@hc
CyrenW32/Agent.BCI.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BIKE
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Graftor.497538
AvastWin32:Kryptik-MSQ [Trj]
TencentTrojan.Win32.Agent.afi
EmsisoftGen:Variant.Graftor.497538 (B)
BaiduWin32.Trojan.Kryptik.ac
VIPREGen:Variant.Graftor.497538
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b48b2a06c5bda943
SophosMal/EncPk-AIT
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Kryptik.PS
JiangminTrojan/ShipUp.vk
Antiy-AVLTrojan/Win32.ShipUp
ArcabitTrojan.Graftor.D79782
ZoneAlarmVHO:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeTrojan-FCWH!B48B2A06C5BD
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Zbot
Cylanceunsafe
RisingTrojan.Kryptik!1.A949 (CLASSIC)
IkarusWin32.Kryptik
MaxSecureTrojan.ShipUp.gen
FortinetW32/Zbot.FG!tr
AVGWin32:Kryptik-MSQ [Trj]
Cybereasonmalicious.6c5bda
DeepInstinctMALICIOUS

How to remove Graftor.497538?

Graftor.497538 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment