Malware

How to remove “Graftor.715739”?

Malware Removal

The Graftor.715739 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.715739 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

a1.chinavipsoft.com

How to determine Graftor.715739?


File Info:

crc32: F5B74BB0
md5: 71aa7e7ad0a6355eb965da35c39720c1
name: setup_zhbglxnb001.exe
sha1: 0722d801d64cb26f34a3ee3ff3fc7eaebd468515
sha256: 1d6bbdb11b7772e33fd3428e54d7a1e4096d4f2228a9d57bca9cf0f9b3d117d0
sha512: 70b2617a75fbba5226e6e709a68c9abc5a6e6d201970770caf4b27edab854f7a312d297c49de9b2eaa62557cb8922ac0aa1e06ee659be3eee1f345eea082fa0c
ssdeep: 196608:6FbGYEA5halz5t7WIU7j/ml3x71rjANi+6:+TzWn7OWlui+6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: x4e2dx534ex529ex516cx6a21x677f
FileVersion: 1.0.7.11120
CompanyName: x4e2dx534ex529ex516cx6a21x677f
ProductName: x4e2dx534ex529ex516cx6a21x677f
ProductVersion: 1,0,7,11120
FileDescription: x4e2dx534ex529ex516cx6a21x677f
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Graftor.715739 also known as:

MicroWorld-eScanGen:Variant.Graftor.715739
McAfeePUP-XJM-AR
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005585a51 )
BitDefenderGen:Variant.Graftor.715739
K7GWAdware ( 005585a51 )
Invinceaheuristic
SymantecPUA.Gen.2
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Graftor.715739
Kasperskynot-a-virus:Downloader.Win32.Agent.memr
AlibabaDownloader:Win32/Softcnapp.37eb1cba
ViRobotAdware.Softcnapp.6742328
TencentMalware.Win32.Gencirc.10b89478
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.715739 (B)
ZillyaAdware.Burden.Win32.340
McAfee-GW-EditionPUP-XJM-AR
MaxSecureTrojan.Malware.74168012.susgen
FireEyeGen:Variant.Graftor.715739
SophosGeneric PUA AH (PUA)
IkarusPUA.Softcnapp
CyrenW32/Trojan.ZNMV-9250
JiangminDownloader.Agent.mwn
WebrootW32.Adware.Gen
Antiy-AVLGrayWare[AdWare]/Win32.Burden
MicrosoftPUA:Win32/CoinMiner
ArcabitTrojan.Graftor.DAEBDB
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.memr
AhnLab-V3PUP/Win32.Agent.C3908931
ALYacGen:Variant.Graftor.715739
VBA32BScope.Adware.Softcnapp
MalwarebytesAdware.ChinAd
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Softcnapp.BA potentially unwanted
RisingPUA.CoinMiner!8.4639 (CLOUD)
YandexRiskware.Agent!
FortinetAdware/Burden
Ad-AwareGen:Variant.Graftor.715739
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Graftor.715739?

Graftor.715739 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment