Malware

How to remove “Graftor.718336”?

Malware Removal

The Graftor.718336 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.718336 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Modifies boot configuration settings
  • Network activity detected but not expressed in API logs
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.718336?


File Info:

crc32: C17730E6
md5: c51eaa632907ace8cc2108f352329e12
name: oneoff.exe
sha1: e710e686675407aa7df879ff97bcb71d1f268b36
sha256: f2e64ada28f2cf2d733585628a20a368f2cf4bd30cfe98caedc3c95295e6fa34
sha512: 2d42d34018eb078d194825c97ac7c1ad1851fd33ca1f6dd370730e1c3b06efa076215128bb60a0acef575e66835410f1efd05f4016a00084b4f7a336a1a4d8e8
ssdeep: 96:wIywlxbyr8m/DpF0NjzZZjTN/iZ66hfl9RDAAKulAq3pGHf3s7fhnOxhaf8Q:wJM5yr8ptzDNq6iflvKc9GHA0naT
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Graftor.718336 also known as:

MicroWorld-eScanGen:Variant.Graftor.718336
FireEyeGeneric.mg.c51eaa632907ace8
CylanceUnsafe
K7AntiVirusTrojan ( 0051918e1 )
BitDefenderGen:Variant.Graftor.718336
K7GWTrojan ( 0051918e1 )
Invinceaheuristic
APEXMalicious
GDataWin32.Application.PUPStudio.A
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.b3693ac3
TencentWin32.Trojan.Generic.Svra
Endgamemalicious (high confidence)
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.718336 (B)
IkarusTrojan-Downloader.Win32.Small
MAXmalware (ai score=87)
ArcabitTrojan.Graftor.DAF600
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftProgram:Win32/Uwasson.A!ml
AhnLab-V3Malware/Win32.Generic.C3662795
Acronissuspicious
ALYacGen:Variant.Graftor.718336
Ad-AwareGen:Variant.Graftor.718336
RisingMalware.Heuristic!ET#82% (RDMK:cmRtazqsnAtAhjdvjqVwtslljGTi)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_87%
BitDefenderThetaGen:NN.ZexaF.34106.aqKfaen0!tab

How to remove Graftor.718336?

Graftor.718336 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment