Malware

Graftor.972689 information

Malware Removal

The Graftor.972689 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.972689 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Graftor.972689?


File Info:

name: 971518390EFB6B50ED9E.mlw
path: /opt/CAPEv2/storage/binaries/6cb572ab3cc107e0bd3a4eaeb455581234052bcb78ec56766d79c14b44f43bc9
crc32: 88D281B6
md5: 971518390efb6b50ed9e504fdd2871c0
sha1: 3ef9593d67ea4cad7fca52e2fb35d3baaa6a6d54
sha256: 6cb572ab3cc107e0bd3a4eaeb455581234052bcb78ec56766d79c14b44f43bc9
sha512: 29f42d6d90ee42374b72d536498fe6ef1eda91676b2558bcbeb7a30c1a06a4ae12143b9609bd4ea2c88952762d9d9378506719193f64737357bcc4e4ef7298be
ssdeep: 98304:c/0I6AJGQJqu6CFLVYu9EllJ3Qw8D7w2/bXLGKXrIY7G2w3E:c8srNYZlJ3ng82/b7FXUMG21
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15826338E956C7C1BE26447F83D242B65906DC04C222F79E6C3D962B6723E1FD432B674
sha3_384: 2f1623298c0bc94f9e55ef52369a55fc240c8a33f5f665bae07e28d6ba9ffa5c82d6503402632cb86d85689264957359
ep_bytes: be000000005381c2c35f45075821c929
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Graftor.972689 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Graftor.972689
FireEyeGen:Variant.Graftor.972689
ALYacGen:Variant.Zusy.361037
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3649713
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.90efb6
BitDefenderThetaGen:NN.ZexaF.34114.@pZ@amPuiRk
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
AvastWin32:CoinminerX-gen [Trj]
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Graftor.972689
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Zusy.361037
EmsisoftGen:Variant.Graftor.972689 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/HckPk-A
GDataGen:Variant.Fragtor.22053
JiangminTrojan.Copak.iut
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Kryptik.ffp
MicrosoftTrojan:Win32/Injector.RAQ!MTB
AhnLab-V3Malware/Gen.Reputation.C4303086
McAfeeGenericRXAA-FA!971518390EFB
MAXmalware (ai score=83)
VBA32Trojan.Packed
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Kryptik!qeUTmYuNe6Y
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Graftor.972689?

Graftor.972689 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment