Malware

About “Graftor.497644” infection

Malware Removal

The Graftor.497644 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.497644 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Graftor.497644?


File Info:

name: E5EE945009D1B54C8A23.mlw
path: /opt/CAPEv2/storage/binaries/92ad43bbf44b15b1da537e7f744f93ac8ad0dd671191ad409fe53ce6370052ac
crc32: 83DA6513
md5: e5ee945009d1b54c8a23064d4183a564
sha1: 5c06f22acc8ae7261fa68d87470e21f791e39b53
sha256: 92ad43bbf44b15b1da537e7f744f93ac8ad0dd671191ad409fe53ce6370052ac
sha512: f5349a98b1244e26cd54f759d4c314e6273d7ae6584cbda01cb80d40f54bd528ef7b539e93a061d3210b7ea15320cb7b5d097b0b41e862aabd60c18f3a88d7f6
ssdeep: 24576:f+naOB9BWOtDeSh9xxc0F01RzV9E6Z6B4m6l1:WlD5KCu6mmi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107454906F98289B7C9800830C4FB57367A769E832F15CB97A358FD357C236536A6B1C9
sha3_384: 6f063b2c3a62275d088cac17940a4d1061cd43741278cbc855ca5c397e2fe314a7f711e09ae40e0bd49f51d99bf71206
ep_bytes: 558bec6aff68c0e44e006884c74a0064
timestamp: 2013-03-29 11:36:31

Version Info:

FileVersion: 1.0.0.0
FileDescription: Sun打码端
ProductName: Sun打码端
ProductVersion: 1.0.0.0
CompanyName: Yfnet
LegalCopyright: Sun打码端
Comments: Sun打码端
Translation: 0x0804 0x04b0

Graftor.497644 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.497644
CAT-QuickHealRisktool.Flystudio.18827
SkyhighBehavesLike.Win32.Generic.th
McAfeeTrojan-FDRA!E5EE945009D1
Cylanceunsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.acc8ae
ArcabitTrojan.Graftor.D797EC
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Graftor.497644
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Graftor.497644 (B)
DrWebTrojan.DownLoader11.11699
VIPREGen:Variant.Graftor.497644
FireEyeGeneric.mg.e5ee945009d1b54c
SophosGeneric ML PUA (PUA)
IkarusTrojan-Dropper.Agent
VaristW32/Trojan.CLL.gen!Eldorado
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumBackdoor.Win32.Hupigon.rgqw@4pfs4h
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Graftor.497644
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.kv0@aiUC2Ecb
ALYacGen:Variant.Graftor.497644
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.98 (RDML:fkr98kcjXC9LKAn0g+YDTw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Graftor.497644?

Graftor.497644 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment