Malware

Graftor.676615 malicious file

Malware Removal

The Graftor.676615 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.676615 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

api.ip138.com
down.xiald.com
down.popodi.com
ab.popodi.com
52740.png

How to determine Graftor.676615?


File Info:

crc32: 3C60239E
md5: f4c135efea1926c61de14338b3d25503
name: 25c625c125c425bb25c225bc25-19-52740appjv.exe
sha1: 660f65c432d1f068c89768377b374dc15e2cad5d
sha256: 0ba84cad39d9d7b12fb17c9f318a004368b096eb8897a184c082cccff9c03727
sha512: e9cbc12ecb024cb35532bcf611456fa87d193dd64b5581e08f0f2913cd29276f882bdec24262f7c662f023b3860694fe1537ff84ce521f6cb77832c39557d109
ssdeep: 49152:x30WcdFBDGzpI92ArEDPuetadb7uEHWA3Zw+:xkWO9GzpI2Tueta9mAF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x9ad8x901fx4e0bx8f7dx5668
FileVersion: 1.2.5.19117
CompanyName: x9ad8x901fx4e0bx8f7dx5668
ProductName: x9ad8x901fx4e0bx8f7dx5668
ProductVersion: 1,2,5,19117
FileDescription: x9ad8x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Graftor.676615 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Graftor.676615
FireEyeGen:Variant.Graftor.676615
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Graftor.676615
MalwarebytesPUP.Optional.Softcnapp
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusAdware ( 004d97001 )
BitDefenderGen:Variant.Graftor.676615
K7GWAdware ( 004d97001 )
TrendMicroTROJ_GEN.R007C0PJ819
CyrenW32/Trojan.YXTV-8277
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R007C0PJ819
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
ViRobotAdware.Softcnapp.1953080.B
TencentWin32.Trojan.Generic.Eegv
Ad-AwareGen:Variant.Graftor.676615
SophosSoftcnapp (PUA)
ComodoMalware@#2s8zimuyntskz
DrWebAdware.Softcnapp.97
ZillyaTrojan.Generic.Win32.956006
Invinceaheuristic
McAfee-GW-EditionGenericRXHC-RW!F4C135EFEA19
EmsisoftGen:Variant.Graftor.676615 (B)
APEXMalicious
GDataGen:Variant.Graftor.676615
JiangminTrojan.APosT.kg
WebrootW32.Adware.Gen
MicrosoftPUA:Win32/CoinMiner
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.Win32.Generic
SentinelOneDFI – Malicious PE
AhnLab-V3Malware/RL.Generic.R257946
McAfeeGenericRXHC-RW!F4C135EFEA19
VBA32BScope.Adware.Puwaders
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
RisingPUA.Puamson!8.108E8 (C64:YzY0Ogwm3dDzhWGI)
IkarusPUA.Softcnapp
eGambitUnsafe.AI_Score_97%
FortinetRiskware/Softcnapp
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Graftor.676615?

Graftor.676615 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment