Adware

Should I remove “Adware.Graftor.165482”?

Malware Removal

The Adware.Graftor.165482 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.165482 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Adware.Graftor.165482?


File Info:

name: B6ED9FA0AC2346E36B3B.mlw
path: /opt/CAPEv2/storage/binaries/b4c185992d31f0d4065fbee8abb49783dacd402cb1123dc6c459a0a5f8994b90
crc32: A1273F89
md5: b6ed9fa0ac2346e36b3bfad220c4cc55
sha1: 0b346249621ca2d12d89110fdee6594a76d0f24e
sha256: b4c185992d31f0d4065fbee8abb49783dacd402cb1123dc6c459a0a5f8994b90
sha512: 9a9af68994c5dafc017957c3619503b95a477c21e6422c80493ef3f70f4d2bcf835c6f3d489b1150ea62cf7767b756ee8c6753939a2f215ed5c868f8c93e63f5
ssdeep: 1536:1O8wQrG5lK2sBTUdwJ5F+ieXSpsLHKIcDIgoDLXU+o2m2dGDW4UqWqx974/fttBw:QQr0VLUKkSKIcDIjH7g7vZx9EteO2v5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E14C5643FC8CDA2F396803512B49AF4D567EDA90B6340A7EB7FB07A937CE443A56101
sha3_384: e72f0e01955956a463441b2a86795b25130b2cc52ca836fb5d109a2256e813acbe265ee88f112c05407decfc5f7ce155
ep_bytes: 558bec6aff68688a410068606f400064
timestamp: 2014-11-11 12:24:32

Version Info:

Comments:
CompanyName:
FileDescription: Z Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: Z
LegalCopyright: 版权所有 (C) 2014
LegalTrademarks:
OriginalFilename: Z.EXE
PrivateBuild:
ProductName: Z 应用程序
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Adware.Graftor.165482 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Graftor.165482
FireEyeGeneric.mg.b6ed9fa0ac2346e3
ALYacGen:Variant.Adware.Graftor.165482
VIPREGen:Variant.Adware.Graftor.165482
SangforTrojan.Win32.Agent.buxin
K7AntiVirusAdware ( 004bca6d1 )
BitDefenderGen:Variant.Adware.Graftor.165482
K7GWAdware ( 004bca6d1 )
CrowdStrikewin/grayware_confidence_100% (W)
CyrenW32/A-8bad6172!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Zmeida.C
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Plugin.ecrqos
RisingTrojan.Occamy!8.F1CD (TFE:5:mbBExLXqgxE)
Ad-AwareGen:Variant.Adware.Graftor.165482
ComodoApplicUnwnt@#33om2csjpwmg1
DrWebAdware.Plugin.604
ZillyaDownloader.Agent.Win32.230657
EmsisoftGen:Variant.Adware.Graftor.165482 (B)
JiangminTrojan.Generic.dlgel
AviraTR/Graftor.troxx
MAXmalware (ai score=61)
Antiy-AVLTrojan/Generic.ASMalwS.30AF
GDataGen:Variant.Adware.Graftor.165482
GoogleDetected
VBA32suspected of Trojan.Downloader.gen
PandaTrj/Chgt.L
TencentMalware.Win32.Gencirc.10c4b8a1
YandexPUA.Plugin!2GRdFYmIMSk
Ikarusnot-a-virus:Downloader.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Agent
BitDefenderThetaGen:NN.ZexaF.34646.mq0@aCFWfPkb
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.0ac234
AvastWin32:Adware-gen [Adw]

How to remove Adware.Graftor.165482?

Adware.Graftor.165482 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment