Malware

Should I remove “Graftor.691981”?

Malware Removal

The Graftor.691981 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.691981 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine Graftor.691981?


File Info:

name: F036549DF312F144822C.mlw
path: /opt/CAPEv2/storage/binaries/f59b5500e7d55f99c703e019699cfeb6e5a18a586bf6ea9ea711f71e3876838f
crc32: 5438AC5E
md5: f036549df312f144822cc748d12babfe
sha1: 7807425aa8be2abbb6c4276939eeb1d136626b88
sha256: f59b5500e7d55f99c703e019699cfeb6e5a18a586bf6ea9ea711f71e3876838f
sha512: 7dddbedd9be88947fbb1d1bead6bbeac702da6829e4c19dcb2c45d794265ea5807ff0c1b3d2b29ce4aab6fac7c8f80995ca1933653ce06f678be63a0ba0ed002
ssdeep: 49152:XkmZWyAHVA7Xk++Qm49s+fVfPG2bN0iBP37DAO4pWGcamzbGba+Yy08D4OE5AGU3:XLWyFrXIOG+0yo1QGcdQa+Yy0805AGUZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4C5331862596968E0C72D3EA34DB2C0DDCD3F638EE5A9898D52C5D850F5ED2FAC1C07
sha3_384: 3d5cb91de3c167e39bb95fcfb260ff9971d1740c2430bbd7cc1f94fd323e53e115d1fe5bdc897dc0fad6ccf9c4e55f8a
ep_bytes: 60be002069008dbe00f0d6ff5783cdff
timestamp: 2022-01-05 00:57:45

Version Info:

FileVersion: 1.0.0.0
FileDescription: Auto Setup
ProductName: Auto Setup
ProductVersion: 1.0.0.0
CompanyName: KoR
LegalCopyright: Null
Comments: Auto Setup
Translation: 0x0804 0x04b0

Graftor.691981 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.691981
FireEyeGeneric.mg.f036549df312f144
ALYacGen:Variant.Graftor.691981
CylanceUnsafe
ArcabitTrojan.Graftor.DA8F0D
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Graftor.691981
Ad-AwareGen:Variant.Graftor.691981
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Sytro.vc
EmsisoftGen:Variant.Graftor.691981 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1243595
Antiy-AVLTrojan[Banker]/Win32.BlackMoon.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.Agent.WP
CynetMalicious (score: 100)
MAXmalware (ai score=80)
VBA32BScope.Backdoor.BlackMoon
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazpizsSXTliqcEcDdrXnzUpM)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ESFJ!tr
BitDefenderThetaGen:NN.ZexaCO.34212.LoKfaCyejCfj
Cybereasonmalicious.df312f

How to remove Graftor.691981?

Graftor.691981 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment