Malware

Graftor.896648 information

Malware Removal

The Graftor.896648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.896648 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Graftor.896648?


File Info:

name: C9B5DFB6715BE4E61055.mlw
path: /opt/CAPEv2/storage/binaries/208c43e9f4d22f2a8f04f6a8bfdcc524010fb2501e797e093d6e53bea21b0ae0
crc32: E9482E43
md5: c9b5dfb6715be4e610555f3bfa12d383
sha1: d04b943bcf1275a26d2c753085cd9ba3a078d7f6
sha256: 208c43e9f4d22f2a8f04f6a8bfdcc524010fb2501e797e093d6e53bea21b0ae0
sha512: 3153c4e3cf786b18f33701c89cbedc3152b7c70b11a2b8fd1cc604cd597ff54d81b99a18d81ea5408b5a5530d50fa18a7ec69d782ab82679b906491eeef3fe1d
ssdeep: 49152:fJh+LWB3M4j4oBfVlH4IuDZvvTQ1D1TLGKMmwWMMckXT+s8KuqGaX0ToIBAUZLYr:X6lvvU1D5SKMzKpoJBAUZL4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157166C33E001C062D75909B02275863D6A79AEA15AB4C893EFE8FDB5EC73923D3E541D
sha3_384: c2ecad44bb4cb50c5d72802206d6bf95e48c3a452da63af37ad2fd25b1cbc34b7ec9fd9eb62fcd8ec64e4d0a810ef816
ep_bytes: 558bec6aff68707d7c0068b410630064
timestamp: 2022-09-23 17:40:54

Version Info:

FileVersion: 1.0.0.0
FileDescription: 企鹅全秒
ProductName: 企鹅全秒
ProductVersion: 1.0.0.0
CompanyName: 企鹅
LegalCopyright: 本程序内核由深圳市腾讯计算机系统有限公司所有
Comments: 企鹅全秒
Translation: 0x0804 0x04b0

Graftor.896648 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.896648
CAT-QuickHealRisktool.Flystudio.17330
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.6715be
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
BitDefenderGen:Variant.Graftor.896648
Ad-AwareGen:Variant.Graftor.896648
EmsisoftGen:Variant.Graftor.896648 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
VIPREGen:Variant.Graftor.896648
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c9b5dfb6715be4e6
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18JA6Q4
JiangminTrojan/PSW.QQPass.pww
GoogleDetected
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Graftor.DDAE88
MicrosoftTrojan:Win32/Sabsik.EN.D!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R429293
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Graftor.896648
MAXmalware (ai score=82)
MalwarebytesMalware.AI.1320607851
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34698.@t0@aCB96glb
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Graftor.896648?

Graftor.896648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment