Malware

Graftor.31129 removal

Malware Removal

The Graftor.31129 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.31129 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Graftor.31129?


File Info:

name: 84AAB0BF18C48FCFC175.mlw
path: /opt/CAPEv2/storage/binaries/eae062d2dd188a7b82be6e8bd0f817387c90fdbfeadb6da57e18641edf3e8b10
crc32: 70B2A118
md5: 84aab0bf18c48fcfc17556baaeb45e72
sha1: bc7783fa5d157b45b99f1c64f082b41da8ba03ac
sha256: eae062d2dd188a7b82be6e8bd0f817387c90fdbfeadb6da57e18641edf3e8b10
sha512: 2438220bbe81cfccbb3da9db91f13ac961c1f013e27ffd2c627edafcc835faffef1f18a9dcf80aee986f7855105e240e7e0ab9d3ffc8bd5adb8bf394d86d330e
ssdeep: 3072:1Zr97TeKgCi8RhgAWIY3Lab00WLZr97TeKgCjjn:X5TxL99+x5TxLX
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1BE84AF23F690C9B3D1A10ABC8C27C58AA93AFD206D3C545676E97F0E8D7A2C14D1D2D7
sha3_384: 174fe2cbaf62957b8983cf9c2639488d90b5c7a133ff43e74e83aeb06f5a8766ff95b130c694ca5f16df89a1122b0ae0
ep_bytes: 807c2408010f857d01000060be004041
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Graftor.31129 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.31129
ClamAVWin.Malware.Lmir-7595062-0
FireEyeGeneric.mg.84aab0bf18c48fcf
CAT-QuickHealWorm.Fasong.S6099
SkyhighBehavesLike.Win32.Generic.ft
McAfeePWS-LegMir.ao
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Graftor.31129
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00009c9e1 )
K7GWTrojan ( 00009c9e1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-PSW.OLGames.bk
VirITTrojan.Win32.Legendmir.AHY
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Fasong.H
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.Lmir.ans
BitDefenderGen:Variant.Graftor.31129
NANO-AntivirusTrojan.Win32.Lmir.cynzy
AvastWin32:Lmir-HJ [Trj]
TencentTrojan.Win32.Lmir.ka
SophosTroj/Fasong-D
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Legmir.428
ZillyaTrojan.Legendmir.Win32.861
TrendMicroTROJ_LDMIR.AC
EmsisoftGen:Variant.Graftor.31129 (B)
IkarusTrojan-PWS.Win32.Lmir
GDataWin32.Trojan.PSE.1AZ1F8F
JiangminTrojan/PSW.LMir.are
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[GameThief]/Win32.Lmir
XcitiumTrojWare.Win32.PSW.Lmir.~BY@g61k5
ArcabitTrojan.Graftor.D7999
ViRobotTrojan.Win32.PSWLmir.103133
ZoneAlarmTrojan-GameThief.Win32.Lmir.ans
MicrosoftPWS:Win32/Lmir
VaristW32/Legendmir.PFXN-4012
AhnLab-V3Trojan/Win32.Lmirhack.R49486
BitDefenderThetaAI:Packer.23BBDB411F
ALYacGen:Variant.Graftor.31129
MAXmalware (ai score=83)
VBA32TrojanPSW.Lmir
Cylanceunsafe
PandaTrj/Legmir.PR
TrendMicro-HouseCallTROJ_LDMIR.AC
RisingWorm.Fasong!1.D14C (CLASSIC)
YandexTrojan.PWS.Lmir!Nw/Lmaa+790
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Lmir.ANS!tr.pws
AVGWin32:Lmir-HJ [Trj]
DeepInstinctMALICIOUS

How to remove Graftor.31129?

Graftor.31129 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment