Malware

Graftor.744589 (B) (file analysis)

Malware Removal

The Graftor.744589 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.744589 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Graftor.744589 (B)?


File Info:

name: 3B7D9CAFD5E269C2DD6C.mlw
path: /opt/CAPEv2/storage/binaries/0108550069d0fb40462c8b2f580afbc434681c2ee3744cadc10145e2450877f8
crc32: 8F3D09F7
md5: 3b7d9cafd5e269c2dd6c84b2344c7c1f
sha1: c5d40cd84385ce6c3082031f49069ec5d89a7dbd
sha256: 0108550069d0fb40462c8b2f580afbc434681c2ee3744cadc10145e2450877f8
sha512: 16652956f2c070b61e67a0d8eea1a639407f7d22237c80467f60506f87a0013b703690de8fbe4cfa7b154139c739b456384854cb90a42a81a071efc014efccce
ssdeep: 49152:lJxGe4VsHz4G0C9csFw0i7OONFSfTjQ9XtmwxMt:kKHz4GrOsFw0i7OAcfTjQM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6B5BE03FA9280F6D618553015BB673AAFB29B421A24CF97D795DE782C33680DB3721D
sha3_384: e09432f6a257fa0541baffa0e4a427b865ca7be1f831bbbe5cbd57d82cc72fc70cd9decfed2b1f59769b72d7c9cf6fe0
ep_bytes: 558bec6aff680086620068d8a14c0064
timestamp: 2022-01-27 08:41:08

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: TB
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Graftor.744589 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.744589
CAT-QuickHealDownloader.AdLoad.12395
ALYacGen:Variant.Graftor.744589
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.744589
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazrI2LI/hspsLL99Sz5BeorN)
EmsisoftGen:Variant.Graftor.744589 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen7.57491
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.3b7d9cafd5e269c2
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.boxs
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Application.PUPStudio.A
CynetMalicious (score: 100)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.ELG!tr.pws
BitDefenderThetaGen:NN.ZexaF.34182.ws0@aqHKi7cb
AVGWin32:Malware-gen
Cybereasonmalicious.fd5e26
AvastWin32:Malware-gen

How to remove Graftor.744589 (B)?

Graftor.744589 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment