Malware

What is “Graftor.71689”?

Malware Removal

The Graftor.71689 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.71689 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs

How to determine Graftor.71689?


File Info:

crc32: B35B11E9
md5: e9680e28f7ecae3988758a2a1a2185f5
name: zhandi.exe
sha1: ced0f0fe45c991da3b24167330d85fe1ea2fcbc2
sha256: 827a68a523be1282ab7de25f659821419f810b0a9780ad0dae932ab53738b729
sha512: a9c8beee3cc6d0b6b99b2b05188ffa52c55222c07045e130d6eac93409fbf175831dea31a0820c4403b77081402baececdc68508d7c6a0f27812e382f4adbdf5
ssdeep: 49152:wkUeO2Owf+luj6pUmJhM0vkpvb8zvapjOo6qXeUEvhSGQXmzzT:wkUeO2Tf+dDE0viv4zvUjOoJO3vhSpm
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: @x4feex6539x5668
FileVersion: 1.0.0.0
CompanyName: x571fx8c46
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: 4399x6218x5730x8054x76dfx4feex6539x5668
ProductVersion: 1.0.0.0
FileDescription: 4399x4feex6539x5668
Translation: 0x0804 0x04b0

Graftor.71689 also known as:

TotalDefenseWin32/PackedBaidu
MicroWorld-eScanGen:Variant.Graftor.71689
FireEyeGeneric.mg.e9680e28f7ecae39
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!E9680E28F7EC
AegisLabTrojan.Win32.Banload.4!c
BitDefenderGen:Variant.Graftor.71689
K7GWAdware ( 0050718d1 )
K7AntiVirusAdware ( 0050718d1 )
NANO-AntivirusTrojan.Win32.Banload.fhtckd
CyrenW32/Agent.EW.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R007C0WJH18
Paloaltogeneric.ml
ClamAVWin.Trojan.Kuping-6633833-0
KasperskyTrojan-Downloader.Win32.Banload.abfvt
AlibabaTrojanDownloader:Win32/Banload.97e28269
ViRobotTrojan.Win32.Z.Graftor.2129408
TencentWin32.Trojan-downloader.Banload.Akyq
Ad-AwareGen:Variant.Graftor.71689
SophosGeneric PUA MO (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.Siggen8.21930
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Graftor.71689 (B)
GDataWin32.Application.PUPStudio.A
MAXmalware (ai score=99)
Antiy-AVLTrojan[Packed]/Win32.FlyStudio
MicrosoftProgram:Win32/Uwamson.A!ml
Endgamemalicious (moderate confidence)
ArcabitTrojan.Graftor.D11809
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
ZoneAlarmTrojan-Downloader.Win32.Banload.abfvt
Acronissuspicious
VBA32BScope.Trojan.Fuerboos
ALYacGen:Variant.Graftor.71689
PandaTrj/GdSda.A
RisingMalware.Undefined!8.C/N3#90% (RDM+:cmRtazpIg9/YlmQ88g1DMFdsWooK)
YandexTrojan.Pasta.Gen.1
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetRiskware/Application
AVGFileRepMalware
Cybereasonmalicious.8f7eca
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Downloader.ff0

How to remove Graftor.71689?

Graftor.71689 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment