Adware

Adware.Graftor.693113 removal guide

Malware Removal

The Adware.Graftor.693113 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.693113 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
crl.verisign.com
s1.symcb.com
download.u7pk.com
2018.ip138.com
www.ip138.com

How to determine Adware.Graftor.693113?


File Info:

name: 7A6B4ACA22DBB72DECC1.mlw
path: /opt/CAPEv2/storage/binaries/07a27997ed444af87a8b34b67ebcace303cf1898cd2aac0c0c045761a9299370
crc32: B61D5E8B
md5: 7a6b4aca22dbb72decc15b28a4be91ba
sha1: 7321f8a1f14767c55af51d482e98346dc0ec5a0e
sha256: 07a27997ed444af87a8b34b67ebcace303cf1898cd2aac0c0c045761a9299370
sha512: 92be2bf33e5066037f3b3f2e161d464e162c63b6b4094ac989092714548706eec47db2dd4e82d0705431ce66c254f332e50279a46eadddb5e59ae425f7b54e81
ssdeep: 12288:ivLUqrbM9foMElKFpCYOMO+0cuUS7UfC1oSx:7ozlKFrOvcNS7U65
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1942387077D9877E9CD8DBC159AE11DDCB7E3E039D8A21301A44996A9D3B023B0C9DE
sha3_384: 4250ad83cb9a813b31df3d7aa70f3d082c8a50ca472c3e3b4ae499b57aaecbb43faf24662108b003031e36ec7317eb59
ep_bytes: 60be00404b008dbe00d0f4ff5789e58d
timestamp: 2018-09-10 05:53:22

Version Info:

Comments:
CompanyName:
FileDescription: tnoc Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 2
InternalName: tnoc
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename: tnoc.EXE
PrivateBuild:
ProductName: tnoc 应用程序
ProductVersion: 1, 0, 0, 2
SpecialBuild:
Translation: 0x0804 0x04b0

Adware.Graftor.693113 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Graftor.693113
FireEyeGeneric.mg.7a6b4aca22dbb72d
CAT-QuickHealTrojan.MauvaiseRI.S5264031
McAfeeArtemis!7A6B4ACA22DB
CylanceUnsafe
SangforTrojan.Win32.Occamy.C07
K7AntiVirusAdware ( 005420991 )
AlibabaAdWare:Win32/Zzinfor.5a77a11a
K7GWAdware ( 005420991 )
Cybereasonmalicious.a22dbb
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Adware.Zzinfor.T
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderGen:Variant.Adware.Graftor.693113
NANO-AntivirusTrojan.Win32.Mlw.fmxwpk
AvastWin32:DangerousSig [Trj]
Ad-AwareGen:Variant.Adware.Graftor.693113
SophosGeneric PUA HD (PUA)
ComodoMalware@#1v6g3sbdd7cja
DrWebTrojan.DownLoader25.14073
ZillyaAdware.Zzinfor.Win32.97
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionGenericRXDX-SL!F791B8926443
EmsisoftGen:Variant.Adware.Graftor.693113 (B)
GDataGen:Variant.Adware.Graftor.693113
JiangminTrojan.Generic.gsbgr
AviraHEUR/AGEN.1136207
Antiy-AVLTrojan/Win32.Bitrep
GridinsoftRansom.Win32.Occamy.sa
ArcabitTrojan.Adware.Graftor.DA9379
MicrosoftTrojan:Win32/Occamy.C07
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2454655
VBA32Trojan.Bitrep
ALYacGen:Variant.Adware.Graftor.693113
MAXmalware (ai score=99)
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
RisingTrojan.Generic@ML.90 (RDML:yEn/ABO7rfwTmIStLJ87XA)
YandexTrojan.GenAsa!/u6TrKPnzBc
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic_PUA_LD.SL!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/CI.A

How to remove Adware.Graftor.693113?

Adware.Graftor.693113 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment