Adware

About “Adware.Graftor.269847” infection

Malware Removal

The Adware.Graftor.269847 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.269847 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Adware.Graftor.269847?


File Info:

name: D90EA2121AB8050D3D1A.mlw
path: /opt/CAPEv2/storage/binaries/1d10774bc5381ac7383ecc4f311c6b1126f5e71de214bb1df4669c1eca0afd48
crc32: 0BFFEB33
md5: d90ea2121ab8050d3d1aeb8e2af588d0
sha1: 31e3cc53b9c34a8bf83d526e1f85b1130f593e59
sha256: 1d10774bc5381ac7383ecc4f311c6b1126f5e71de214bb1df4669c1eca0afd48
sha512: 1cef8945753cdf38d133268d29f47ee02069e763f89e437f46df509eef12a44ee059a9b6a9654e478260455052b5860abbc98ddb6c20459bf42bbf245c269a91
ssdeep: 1536:jA8N2GX4j0yNqdb5SbVXOS9x909li0dpmmG83CPINwEI2EJY:jfNR4j9qdo1QW0dpa8OzEI5JY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175836D2275D0C072D072653068B9D3A19F7FB9225A75884B77A807BE5F303C19E7A397
sha3_384: fce244a36aa5c0aad2c32d8896106c7831fed90e65dc8a582b0df4ba97324a8a86ce055dc48340c61413c6373ab16a1d
ep_bytes: e836590000e989feffff8bff558bec83
timestamp: 2016-02-07 14:25:07

Version Info:

0: [No Data]

Adware.Graftor.269847 also known as:

MicroWorld-eScanGen:Variant.Adware.Graftor.269847
FireEyeGeneric.mg.d90ea2121ab8050d
McAfeeGenericRXAA-AA!D90EA2121AB8
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 005707f91 )
AlibabaDownloader:Win32/HardLink.acc3f6a9
K7GWTrojan-Downloader ( 005707f91 )
Cybereasonmalicious.21ab80
BitDefenderThetaGen:NN.ZexaF.34712.fuX@aurA2Woi
VirITTrojan.Win32.Generic.ANJF
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.CDM
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:Downloader.Win32.HardLink.gen
BitDefenderGen:Variant.Adware.Graftor.269847
NANO-AntivirusTrojan.Win32.HardLink.fcfkbq
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastWin32:Dropper-gen [Drp]
RisingDownloader.Agent!8.B23 (CLOUD)
Ad-AwareGen:Variant.Adware.Graftor.269847
EmsisoftGen:Variant.Adware.Graftor.269847 (B)
ComodoTrojWare.Win32.TrojanDownloader.Agent.EIGH@6az41z
F-SecureHeuristic.HEUR/AGEN.1224292
ZillyaTrojan.GenericKD.Win32.45
McAfee-GW-EditionBehavesLike.Win32.PUP.mh
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosGeneric PUA DB (PUA)
IkarusTrojan-Downloader.Win32.Agent
GDataGen:Variant.Adware.Graftor.269847
JiangminDownloader.HardLink.o
AviraHEUR/AGEN.1224292
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Adware.Graftor.D41E17
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 99)
VBA32Downloader.HardLink
ALYacGen:Variant.Adware.Graftor.269847
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
TencentMalware.Win32.Gencirc.10b12f01
YandexTrojan.GenAsa!07wLiTkMF1U
MAXmalware (ai score=100)
FortinetW32/TrojanDownloader.CDM!tr
AVGWin32:Dropper-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Adware.Graftor.269847?

Adware.Graftor.269847 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment