Malware

Graftor.759563 removal guide

Malware Removal

The Graftor.759563 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.759563 virus can do?

  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

softlog.twoshadow.cn

How to determine Graftor.759563?


File Info:

crc32: 2B0D443B
md5: 17676d9b74a48aaf68040486423be696
name: setup_screenocr_screenocr02nodkpk_v1.0_silent.exe
sha1: 3fec25d8a6ed42063729bc5acf11e8fcdc1523ba
sha256: 9463862cfa082fd6507cb0f0ace4a45e3f6e9f6cd011271face2bc55d0e95899
sha512: f45b5a6ab851919413c96885ed4419ec5759da309090c518d02090dd34f00c3954dd41e967852fe5d0a880e1d6562563e3701cb53c605a2c6ce82fae9d64aabf
ssdeep: 393216:yy0VACSbxn8q1lDU83JOmFZHYMGaw0bp8O6MuaKJCv6T5Z:QA9B8Yth5L0MGNqpTuK8Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 x4e0ax6d77x5f71x53ccx7f51x7edcx79d1x6280x6709x9650x516cx53f8
InternalName: Setup.exe
CompanyName: x4e0ax6d77x5f71x53ccx7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: ScreenOCR
ProductVersion: 1.0.0.1
FileDescription: ScreenOCRx5b89x88c5x7a0bx5e8f
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

Graftor.759563 also known as:

MicroWorld-eScanGen:Variant.Graftor.759563
FireEyeGen:Variant.Graftor.759563
McAfeeTrojan-FSNQ!17676D9B74A4
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005678571 )
BitDefenderGen:Variant.Graftor.759563
K7GWAdware ( 005678571 )
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.759563
Kasperskynot-a-virus:AdWare.Win32.ComponentBased.b
AlibabaAdWare:Win32/ComponentBased.f9907e95
RisingPUA.Kaobeitu!8.1124B (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.759563 (B)
IkarusTrojan-Downloader.Win32.Adload
CyrenW32/Trojan.OVNU-7455
JiangminAdWare.ComponentBased.ao
WebrootW32.Trojan.Gen
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kaobeitu
ArcabitTrojan.Graftor.DB970B
ZoneAlarmnot-a-virus:AdWare.Win32.ComponentBased.b
VBA32BScope.TrojanDownloader.Adload
ALYacGen:Variant.Graftor.759563
Ad-AwareGen:Variant.Graftor.759563
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kaobeitu.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H07G220
eGambitUnsafe.AI_Score_99%
FortinetAdware/ComponentBased
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Graftor.759563?

Graftor.759563 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment