Malware

Graftor.721779 information

Malware Removal

The Graftor.721779 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.721779 virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

tpop.kpzip.com
tj.kpzip.com

How to determine Graftor.721779?


File Info:

crc32: D0CA0C7B
md5: 854c512b09c17960ca46a8a696722b66
name: tpop-2.exe
sha1: 80cdcc06785e91f6053eb8d341b03fd79fcc8557
sha256: 6c9b8bc1b8e2ea9fe39a2fc4ee05a11e68d759fd8c448c6ba63faac4f4e603db
sha512: 1e7eb92597fe576fcc2a07af7103a19e343f6fdd9c9093cab5a0d8d765c43bb921f3de054e9b6b216da890e77fab3380f898888a44a2c6a110e0a836a7546ec6
ssdeep: 49152:AZ6p5j0xwTQC0rl4pp9ZIJ8V7bie0ynMpO:AZBs0rluyePiI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2010-2019
InternalName: x5c0fx8d34x58eb
FileVersion: 3.1.1.7
ProductName: x5c0fx8d34x58eb
ProductVersion: 3.1.1.7
FileDescription: x5c0fx8d34x58eb
OriginalFilename: x5c0fx8d34x58eb
Translation: 0x0804 0x04b0

Graftor.721779 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Graftor.721779
FireEyeGeneric.mg.854c512b09c17960
McAfeeArtemis!854C512B09C1
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 0055caed1 )
BitDefenderGen:Variant.Graftor.721779
K7GWAdware ( 0055caed1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Graftor.721779
Kasperskynot-a-virus:RiskTool.Win32.KuaiZip.daa
AlibabaBackdoor:Win32/KZip.4f65e2a1
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazoZEEO6AxfffOkMCYgYIW6Q)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.721779 (B)
DrWebProgram.Kuaizip.6
McAfee-GW-EditionArtemis!PUP
IkarusAdWare.KuziTui
WebrootW32.Adware.Gen
ArcabitTrojan.Graftor.DB0373
ZoneAlarmnot-a-virus:RiskTool.Win32.KuaiZip.daa
MicrosoftPUA:Win32/KuaiZip
VBA32BScope.Adware.Burden
ALYacGen:Variant.Graftor.721779
MAXmalware (ai score=84)
Ad-AwareGen:Variant.Graftor.721779
PandaTrj/CI.A
ESET-NOD32a variant of Win32/KuaiZip.U potentially unwanted
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_78%
FortinetRiskware/KuaiZip
AVGWin32:UnwantedSig [PUP]
AvastWin32:UnwantedSig [PUP]

How to remove Graftor.721779?

Graftor.721779 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment