Malware

Graftor.401603 (B) removal tips

Malware Removal

The Graftor.401603 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.401603 (B) virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

ad.qqfarmer.com.cn

How to determine Graftor.401603 (B)?


File Info:

crc32: 7F37F0E0
md5: e980d6b548ef55ff6976ac57d2d2220d
name: E980D6B548EF55FF6976AC57D2D2220D.mlw
sha1: 4ee8bd59c6912f836da09149ad0dc09dfde74da8
sha256: 6e1bd50747bd6d4efa9c5345543c64edfd5a91632f5c2b9923b80598ef8207ff
sha512: 044a93b30f575e26569b5de6d5ca713717fb45a7b7e399e8d6226a30e9a0322802591bc20708ed68813f524b4ba41a84ce82d37a0e4244f662b698bb6d982f78
ssdeep: 24576:O9PcMSDu/hH6bVfg2sm/crV+VmMRNEdtZJcqSu5LXooOSodQxbB19fq4SbT0R9S:kSi/ohggVGhJcu5Toovb9cf/JWQLR0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: www.QQHelper.net
InternalName: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
FileVersion: 1.4.6.103
CompanyName: www.QQHelper.net
LegalTrademarks: www.QQHelper.net
ProductName: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
ProductVersion: 1.0.0.0
FileDescription: QQx519cx7267x9910x4e09x5408x4e00x52a9x624b
OriginalFilename: QQHelper.exe
Translation: 0x0804 0x03a8

Graftor.401603 (B) also known as:

K7AntiVirusAdware ( 004ee0a41 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader27.17381
ALYacGen:Variant.Graftor.401603
CylanceUnsafe
ZillyaTrojan.Generic.Win32.26668
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_90% (D)
K7GWAdware ( 004ee0a41 )
Cybereasonmalicious.548ef5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/QQfarmer.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.401603
NANO-AntivirusTrojan.Win32.QQfarmer.flbazf
MicroWorld-eScanGen:Variant.Graftor.401603
TencentMalware.Win32.Gencirc.10b547d6
Ad-AwareGen:Variant.Graftor.401603
SophosQQHelper (PUA)
BitDefenderThetaGen:NN.ZelphiF.34266.4P0baOVPdGjR
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WGG21
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
FireEyeGen:Variant.Graftor.401603
EmsisoftGen:Variant.Graftor.401603 (B)
JiangminTrojan.Valcaryx.l
WebrootPUA.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1DCAB81
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftExploit:Win32/ShellCode!ml
ArcabitTrojan.Graftor.D620C3
GDataGen:Variant.Graftor.401603
AhnLab-V3Unwanted/Win32.HackTool.R119402
McAfeeGenericRXAA-FA!E980D6B548EF
MAXmalware (ai score=99)
VBA32BScope.Trojan.Click
MalwarebytesAdware.QQHelper
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WGG21
YandexTrojan.Agent!DURZ9HNpYvw
IkarusPUA.QQfarmer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQfarmer.A
AVGWin32:Malware-gen

How to remove Graftor.401603 (B)?

Graftor.401603 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment