Malware

About “Graftor.870920” infection

Malware Removal

The Graftor.870920 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.870920 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Graftor.870920?


File Info:

crc32: 64660D6A
md5: d5487fd9220925664a2e72cc9a3a6dd2
name: D5487FD9220925664A2E72CC9A3A6DD2.mlw
sha1: 6745e23b5995ed02dbe449b4ca3f67452fb0cbd4
sha256: 6f900027d5b97d6b08d75a67c4395c185d60cb4ebe85efda220ffb876b2cbc1d
sha512: baa5b535089aaceef94643bf995a6395c5f46a120f1abbe3d78b3a643e74222f376d9043c07d9345af1d53896ddc6bc581d02ee82bc34c2adc3015a67cbfeb5c
ssdeep: 12288:eVb1VlgjrbQGBv0WkibIwm++8/4xbtOpGyXGAzbhw6Auom8SX:eVbejrb7TbTA8wxbtOwyXVK6Aufv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Qx7fa4xff1a 680337352
FileVersion: 1.0.0.0
CompanyName: x70abx9177x9738x6c14x540ax70b8x5929
Comments: x5c4fx853dx68c0x6d4b
ProductName: x5c4fx853dx68c0x6d4b
ProductVersion: 1.0.0.0
FileDescription: x5c4fx853dx68c0x6d4b
Translation: 0x0804 0x04b0

Graftor.870920 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.870920
FireEyeGeneric.mg.d5487fd922092566
ALYacGen:Variant.Graftor.870920
CylanceUnsafe
BitDefenderGen:Variant.Graftor.870920
Cybereasonmalicious.922092
BitDefenderThetaGen:NN.ZexaF.34590.Qy0baqRbOplb
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
Ad-AwareGen:Variant.Graftor.870920
EmsisoftGen:Variant.Graftor.870920 (B)
McAfee-GW-EditionBehavesLike.Win32.Flyagent.jc
SophosGeneric ML PUA (PUA)
MaxSecureTrojan.Malware.121218.susgen
MicrosoftTrojan:Win32/Wacatac.D6!ml
ArcabitTrojan.Graftor.DD4A08
GDataGen:Variant.Graftor.870920
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R368336
Acronissuspicious
McAfeeArtemis!D5487FD92209
MAXmalware (ai score=81)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.907132334
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Graftor.870920?

Graftor.870920 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment