Malware

About “Graftor.929819 (B)” infection

Malware Removal

The Graftor.929819 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.929819 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

hhb15405.web3v.com

How to determine Graftor.929819 (B)?


File Info:

crc32: 56699C08
md5: 62322f5891f3b6b92f276ed207d4b2ea
name: 62322F5891F3B6B92F276ED207D4B2EA.mlw
sha1: 452ba7137fe9751e6e42387d12a6cc5517563f1c
sha256: b72f678cd4fb87d7a8205e713e8d67f2f6857cddd1981608fae77256a51a08d7
sha512: 0a0e34fc4defaa335a8d92b22c302404f66bdf77ceec943cd9ca0d4568442a58f2c4f2e76462b93ad40c46370793a81fde5a1ce99215c02c3e1915a5045a8c4f
ssdeep: 24576:DxV4SkPIqzdoNdnnVdVoxaXoxJo1grd/l55uHImFxYz4k7e:3kz5snLVosXoxJck/l50VIo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Qx7fa4xff1a680337352
FileVersion: 2.0.0.0
CompanyName: x70abx9177x9738x6c14x540ax70b8x5929
Comments: x4e3ax4e0dx4f1ax5b89x88c5x8986x76d6x7248x63d2x4ef6x7684x7528x6237x5236x4f5cx7684x4e00x6b3ex5b89x88c5x5668
ProductName: x8986x76d6x7248x63d2x4ef6x5b89x88c5x5668
ProductVersion: 2.0.0.0
FileDescription: x4e3ax4e0dx4f1ax5b89x88c5x8986x76d6x7248x63d2x4ef6x7684x7528x6237x5236x4f5cx7684x4e00x6b3ex5b89x88c5x5668
Translation: 0x0804 0x04b0

Graftor.929819 (B) also known as:

Elasticmalicious (high confidence)
ClamAVWin.Malware.Generic-9820446-0
CylanceUnsafe
SangforSuspicious.Win32.Graftor.929819
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Graftor.929819
K7GWAdware ( 0050718d1 )
BitDefenderThetaGen:NN.ZexaF.34590.cz0bayVu9Mpb
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AlibabaRiskWare:Win32/FlyStudio.00c15011
AegisLabRiskware.Win32.Graftor.1!c
EmsisoftGen:Variant.Graftor.929819 (B)
F-SecureTrojan.TR/Redcap.qwlor
DrWebTrojan.DownLoader36.52666
SophosGeneric ML PUA (PUA)
AviraTR/Redcap.qwlor
MicrosoftTrojan:Win32/Wacatac.DB!ml
ArcabitTrojan.Graftor.DE301B
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.cdcb
AhnLab-V3Malware/Gen.RL_Reputation.R368336
Acronissuspicious
ALYacGen:Variant.Graftor.929819
MAXmalware (ai score=85)
MalwarebytesMalware.AI.907132334
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
Cybereasonmalicious.37fe97
Paloaltogeneric.ml

How to remove Graftor.929819 (B)?

Graftor.929819 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment