Malware

Graftor.704502 (file analysis)

Malware Removal

The Graftor.704502 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.704502 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
auth.ailyidc.cn

How to determine Graftor.704502?


File Info:

crc32: F224E5BA
md5: f030f8dc088287fe1d78a55ccdaaac1e
name: ________________________.exe
sha1: 9c476327afe626b01b32327e025ff6675f4c2e1e
sha256: 8c5c63f9f33ed5b158ba2e9c4f832271076a57da92463916bd0b5f748edb4069
sha512: 67e6d645b2b980e1c53b1cb592d6feaab20c47c94df87d17c436fc41a1fc3541d1b23847053bee2fdb1d4acdcd5e05f2cbee4049a6123a9b00620229492de460
ssdeep: 12288:7JMZIU3hmK0EwIW/VVEgV0FL0M/SprFJZCnEu076b6zjEqfgW6gz2k:VMXmFEwI8VCgVcLz/DK26z4qfgW6gzj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: QQ3028290032x7fa4625987787
FileVersion: 1.0.0.0
CompanyName: x9f99x4e91
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x9f99x4ebax4e91x63d2x4ef6x66f4x65b0x5668
ProductVersion: 1.0.0.0
FileDescription: x66f4x65b0x6307x5b9ax63d2x4ef6x4e13x7528
Translation: 0x0804 0x04b0

Graftor.704502 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Graftor.704502
FireEyeGeneric.mg.f030f8dc088287fe
Qihoo-360Generic/HEUR/QVM07.1.F844.Malware.Gen
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Graftor.1!c
SangforMalware
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Graftor.704502
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.7afe62
BitDefenderThetaGen:NN.ZexaF.34108.1q0@aGlC7Ypb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Oflwr.A!crypt
TrendMicro-HouseCallTROJ_GEN.R002H0CEC20
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6840460-0
GDataWin32.Application.PUPStudio.A
KasperskyTrojan.Win32.Agent.xadtuu
TencentWin32.Trojan.Agent.Dziu
Ad-AwareGen:Variant.Graftor.704502
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Graftor.704502 (B)
IkarusPUA.Virbox
F-ProtW32/Agent.EW.gen!Eldorado
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.DABFF6
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
ZoneAlarmTrojan.Win32.Agent.xadtuu
MicrosoftPUA:Win32/Vigua.A
Acronissuspicious
ALYacGen:Variant.Graftor.704502
APEXMalicious
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
RisingTrojan.Generic@ML.95 (RDML:Yf7U1MA6LV3as/PnvHVb9Q)
SentinelOneDFI – Malicious PE
eGambitHackTool.Generic
FortinetW32/QQWare.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Graftor.704502?

Graftor.704502 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment