Adware

Adware.Graftor.249802 information

Malware Removal

The Adware.Graftor.249802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.249802 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Generates some ICMP traffic
  • Anomalous binary characteristics

Related domains:

ad.qqfarmer.com.cn
bakad.qqfarmer.com.cn

How to determine Adware.Graftor.249802?


File Info:

crc32: D2AD23EB
md5: f70f6656b9bb075d42d050efdbd941b0
name: F70F6656B9BB075D42D050EFDBD941B0.mlw
sha1: 70f603ddc6bc839b0b1c2e881a53a2e91b55997d
sha256: ac81bf7666dc57d59298aab12caf350e4bdfa6dc8c2987f21a6f845fe7dc4fea
sha512: 4b2655f461546a9ffea103fa2a09009ee60aee6fc1930bbc74fe01516badd96f85f19d8d05fb2499fce0b38f4d9a50ca816ebfa1386578d92ee776721a60bd82
ssdeep: 24576:/O10p0T1yJUaihtW6xLmzkAo2pDBMABO3/lsS0XjpppIRT6XYLtl9fgxfjTw8DG:E0pmiUKIR2ZBcsSygq0tAtNxf00aR
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: www.QQHelper.net
InternalName: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
FileVersion: 1.4.0.802
CompanyName: www.QQHelper.net
LegalTrademarks: www.QQHelper.net
ProductName: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
ProductVersion: 1.0.0.0
FileDescription: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
OriginalFilename: QQHelper.exe
Translation: 0x0804 0x03a8

Adware.Graftor.249802 also known as:

K7AntiVirusAdware ( 004cfa2e1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Siggen14.63642
CynetMalicious (score: 100)
ALYacGen:Variant.Adware.Graftor.249802
CylanceUnsafe
ZillyaTrojan.Valcaryx.Win32.86
SangforPUP.Win32.Delf.NAF
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/TScope.fd321b57
K7GWAdware ( 004cfa2e1 )
Cybereasonmalicious.6b9bb0
CyrenW32/Hupigon.CG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.Delf.NAF
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Adware.Graftor.249802
NANO-AntivirusTrojan.Win32.Delf.fbjhbc
MicroWorld-eScanGen:Variant.Adware.Graftor.249802
TencentMalware.Win32.Gencirc.10bb5f7e
Ad-AwareGen:Variant.Adware.Graftor.249802
SophosQQHelper (PUA)
ComodoApplicUnwnt@#3deitp618a4kx
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPUP-XFW-YM
FireEyeGen:Variant.Adware.Graftor.249802
EmsisoftGen:Variant.Adware.Graftor.249802 (B)
JiangminTrojan.Valcaryx.v
AviraHEUR/AGEN.1129352
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.343EB39
MicrosoftPWS:Win32/Zbot!ml
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
GDataGen:Variant.Adware.Graftor.249802
AhnLab-V3Unwanted/Win32.HackTool.R119402
McAfeeArtemis!F70F6656B9BB
MAXmalware (ai score=99)
VBA32TScope.Trojan.Delf
MalwarebytesAdware.QQHelper
PandaGeneric Suspicious
YandexTrojan.GenAsa!5yt+/oNnurI
MaxSecureVirus.W32.VB.K
FortinetRiskware/Delf
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Adware.Graftor.249802?

Adware.Graftor.249802 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment