Malware

How to remove “Graftor.691754”?

Malware Removal

The Graftor.691754 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.691754 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Graftor.691754?


File Info:

name: 0703775A8129E8226E28.mlw
path: /opt/CAPEv2/storage/binaries/76e45460d71a7b6678222aeeb695b10b57101f64707badb8226b188acfdd36df
crc32: 326583F0
md5: 0703775a8129e8226e285993efe5b792
sha1: 8920b839f845b91cee1d5d821e300ae6b2e95618
sha256: 76e45460d71a7b6678222aeeb695b10b57101f64707badb8226b188acfdd36df
sha512: 32a9058aacca76a53dda7578bd102c950ee5cf5a16b90a44b24e64d4ee4e726e1df17d6aa943fbde623b995cfee7c7bd58d8683603fca6715d1367a52a28450e
ssdeep: 49152:+SIjsJJSLp9+ZjXIKuX518K6/ILQcGaEPN6A1VxYf4ePzYItavvj:tosJJSLp9GQ518XYv4cATxW4ekItavvj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181D5120276C780F2D721253008B62B7BD9399B050B64EFD39B1CEF689D731E1A63B15A
sha3_384: fa652a6f55c8adc6493d956e395919f10352bd2f9ec4f42f3c70bbc079b71335a63f0a6d5723ff2330398559ad1db4d8
ep_bytes: 558bec6aff6828b96800683091470064
timestamp: 2021-09-20 02:14:06

Version Info:

FileVersion: 1.0.0.157
FileDescription: 定制开发
ProductName: 定制开发
ProductVersion: 1.0.0.157
CompanyName: 定制开发
LegalCopyright: 定制开发
Comments: 定制开发
Translation: 0x0804 0x04b0

Graftor.691754 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lpDo
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.691754
FireEyeGeneric.mg.0703775a8129e822
ALYacGen:Variant.Graftor.691754
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWAdware ( 004b87ea1 )
Cybereasonmalicious.a8129e
CyrenW32/Trojan.KLHR-7138
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderGen:Variant.Graftor.691754
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Graftor.691754
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Graftor.691754 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1THOGOA
AviraHEUR/AGEN.1211193
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Graftor.DA8E2A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4708631
McAfeeArtemis!0703775A8129
MAXmalware (ai score=88)
VBA32BScope.Adware.Downware
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H09IR21
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34182.Rs0@aWWznKpb
AVGWin32:Malware-gen

How to remove Graftor.691754?

Graftor.691754 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment