Malware

How to remove “Application.Graftor.468062”?

Malware Removal

The Application.Graftor.468062 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.468062 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xui.ptlogin2.qq.com
www.beiletoys.com
ocsp.globalsign.com
ocsp2.globalsign.com
crl.globalsign.com

How to determine Application.Graftor.468062?


File Info:

crc32: 6B7F4166
md5: b6e390a8e40b0059a8c1ee71b3b873f1
name: xbQQcs.exe
sha1: 9517a91acefcdbca74df99ae0b0b7f76f247b12f
sha256: 0710ab2457176411859d3beeaba7031f37e853edad722feeb524e9048fd35399
sha512: d8f6265ae8e6171a0fc47e45dfb7eb71ed7dad153c6fab32ba38edf0b68e6102e4ef470814e3c114b52b8b2cca97b8c2fbd947f9de4f043e6ee8cccbc26387ab
ssdeep: 49152:D2oq1Cp+5ber0ohfBU/UottfdslNRQg8VF:D251I+noQ/U4pdslUg8r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: xbQQcs
FileVersion: 6.5.0.0
CompanyName: x5c0fx767dx5de5x4f5cx5ba4
LegalTrademarks:
Comments:
ProductName: x5c0fx767dQQx8d85x5e02x8f85x52a9
ProductVersion: 6.4
FileDescription: x5c0fx767dQQx8d85x5e02x8f85x52a9
OriginalFilename: xbQQcs
Translation: 0x0804 0x03a8

Application.Graftor.468062 also known as:

MicroWorld-eScanGen:Variant.Application.Graftor.468062
FireEyeGeneric.mg.b6e390a8e40b0059
K7AntiVirusTrojan ( 005239691 )
AlibabaPacked:Win32/NoobyProtect.d286af6e
K7GWTrojan ( 005239691 )
Cybereasonmalicious.8e40b0
ArcabitTrojan.Application.Graftor.D7245E
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Noobyprotect-6622929-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Graftor.468062
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareGen:Variant.Application.Graftor.468062
EmsisoftGen:Variant.Application.Graftor.468062 (B)
F-SecureHeuristic.HEUR/AGEN.1006058
McAfee-GW-EditionBehavesLike.Win32.Generic.wm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1006058
MicrosoftTrojan:Win32/Wacatac.B!ml
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Riskware.NoobyProtect.B
Acronissuspicious
McAfeePacked-LF!B6E390A8E40B
MAXmalware (ai score=75)
CylanceUnsafe
ESET-NOD32a variant of Win32/Packed.NoobyProtect.Q suspicious
RisingTrojan.Crypto!8.364 (TFE:3:bba9G7V8wJ)
IkarusPUA.NoobyProtect
FortinetW32/Injector.FKM!tr
BitDefenderThetaGen:NN.ZexaF.32250.vx1@a8n9sVjb
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.Graftor.468062?

Application.Graftor.468062 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment