Malware

What is “Graftor.698115”?

Malware Removal

The Graftor.698115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.698115 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Graftor.698115?


File Info:

name: BBF8838A4E5407D7361D.mlw
path: /opt/CAPEv2/storage/binaries/d44a2b4d5427aca8ec8e7dd4d4a1187adcf9c91f849a9d58fbd4e45f35f7d0ad
crc32: 890BBF71
md5: bbf8838a4e5407d7361d95b7e35bbea7
sha1: 89d6e45ea5df8752b9b74f43427e312ba6aad071
sha256: d44a2b4d5427aca8ec8e7dd4d4a1187adcf9c91f849a9d58fbd4e45f35f7d0ad
sha512: d4bae7f8c950d7b53cb055f620ac8ae1c666e04d42ad02d4d1a2240dca6d63bfb8b44785ef484af4353293845d0210f6cdb1177dd47ea71d42f6aabd1a2d73f8
ssdeep: 24576:U5SzS6UZRnVqfFyySLUt0MhP9O3Oz9AY5daIAaCD0/CYO3Oz9AY5daIAaCD0c1:U5US60qfx5B9O+zfaeu0PO+zfaeu0I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B65BF12666AC0F6C39054705DE2D7BAAE7CDD120F298B83E365FF1C4E367C06E2A159
sha3_384: 90c818f75c90c8afa2563260e850ceb3fefbf889c4113f18b7330901b20bf82ca723596b51ae7d61d1e51166623b9b45
ep_bytes: 558bec6aff6820e04e0068f4dd460064
timestamp: 2022-01-15 12:15:36

Version Info:

FileVersion: 1.0.0.0
FileDescription: 支持所有可见窗口
ProductName: 投屏软件
ProductVersion: 1.0.0.0
CompanyName: 时光斑驳、记忆
LegalCopyright: 时光斑驳、记忆 版权所有
Comments: 微信 时光斑驳、记忆 yhwp86
Translation: 0x0804 0x04b0

Graftor.698115 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.698115
FireEyeGeneric.mg.bbf8838a4e5407d7
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a4e540
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
BitDefenderGen:Variant.Graftor.698115
EmsisoftGen:Variant.Graftor.698115 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
SophosGeneric ML PUA (PUA)
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1THOGOA
ALYacGen:Variant.Graftor.698115
MalwarebytesTrojan.MalPack.FlyStudio
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazoZI7Kp+XmelmgTqCpoAYcd)
YandexTrojan.GenAsa!80Bc7OIv7n4
SentinelOneStatic AI – Malicious PE
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.698115?

Graftor.698115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment