Malware

About “Graftor.9700” infection

Malware Removal

The Graftor.9700 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.9700 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.9700?


File Info:

name: 29195B61AD2E1EDD43AD.mlw
path: /opt/CAPEv2/storage/binaries/0a0b521db1b893a1b639cd6ed2b4f652028ae38ecf851094ac24820c2a914a0f
crc32: 4648E980
md5: 29195b61ad2e1edd43ad35faad066521
sha1: 4e4ef1a17deea75fb1067b02b36ce974bf0c42f4
sha256: 0a0b521db1b893a1b639cd6ed2b4f652028ae38ecf851094ac24820c2a914a0f
sha512: cdc4f3832e1333f2b1df70509eb87c12084ae66fb8b8f55541e2de957e713649c3026ad21b6e7fff1df4f5e267489427f409dd499e3aed4b89bb34abcbaaf458
ssdeep: 24576:TO8jHt8TaKXADVUoATZaqdiXSp0c02uFG6dAk3CMg/kE:TrjHtgwmoATZaqdwk0c05HGig/5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17375E121B6D240FAD625047009BB2B37AA789B521B24CFC397E4DE7D1D33683D93616E
sha3_384: 8b99cba41918cf44d92524111b8760f6978aa8fe14c56e3616673c944ec865db84b6163923facb07da4993905c88d30a
ep_bytes: 558bec6aff68b0ec560068c48e460064
timestamp: 2011-10-15 07:31:37

Version Info:

FileVersion: 2.3.2010.8
FileDescription: 唇晗秒驾照自动多开V3.9
ProductName: 唇晗秒驾照自动多开V3.9
ProductVersion: 2.3.2010.8
CompanyName: 唇晗
LegalCopyright: 唇晗秒驾照自动多开V3.9 本辅只用于娱乐,本软件带来的任何损失,本人概不承担!
Comments: 唇晗秒驾照自动多开V3.9
Translation: 0x0804 0x04b0

Graftor.9700 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.9700
FireEyeGeneric.mg.29195b61ad2e1edd
SkyhighBehavesLike.Win32.Generic.tc
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Graftor.9700
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.9700
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.17deea
BitDefenderThetaGen:NN.ZexaF.36792.Kr0@ayzpLgob
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Flystudio-9943951-0
SophosGeneric ML PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Graftor.9700 (B)
VaristW32/OnlineGames.HG.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Script/Phonzy.B!ml
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Graftor.D25E4
GDataWin32.Trojan.PSE.15IBL0F
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R612236
ALYacGen:Variant.Graftor.9700
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Graftor.9700?

Graftor.9700 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment