Adware

Adware.Graftor.290828 (B) (file analysis)

Malware Removal

The Adware.Graftor.290828 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.290828 (B) virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz
query.run456.com

How to determine Adware.Graftor.290828 (B)?


File Info:

crc32: 2F9D184A
md5: c9a2b6eb0bad24d2112483dae769c1e6
name: Gamestart.exe
sha1: ff192268ae530c5e63df02390b640c73d0b9e466
sha256: 906e9402b06f47c346effaf710da6df1e36d227bca089fbe4826cf58dca6aa00
sha512: 00e4bd9e9a5221e8a8e71b35a577b4f8c26afdc57c11ebaf3904f587f92fc8593b57648d0b97db40642c4f990dc8ac5c7593b0f3e94d87952e4aed0d600cd5ee
ssdeep: 24576:uKUNEataQ7CxaOvEBgCWC1TVQ93z3iA+bquoOsEW0O39sLdNmvmTiQ6BESmiy++:PeEa9CdC1TVQHaDONsLdNlTiQkESnA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: x6e38x620fx5b89x88c5x7a0bx5e8f
FileVersion: 2.3.0.367
ProductName: x6e38x620fx5b89x88c5x7a0bx5e8f
ProductVersion: 2.3.0.367
FileDescription: x6e38x620fx5b89x88c5x7a0bx5e8f
OriginalFilename: setup.exe
Translation: 0x0804 0x04b0

Adware.Graftor.290828 (B) also known as:

MicroWorld-eScanGen:Variant.Adware.Graftor.290828
FireEyeGeneric.mg.c9a2b6eb0bad24d2
ALYacGen:Variant.Adware.Graftor.290828
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 00561ec01 )
BitDefenderGen:Variant.Adware.Graftor.290828
K7GWAdware ( 00561ec01 )
Cybereasonmalicious.b0bad2
TrendMicroTROJ_GEN.R002C0PHJ19
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PHJ19
AvastWin32:Adware-gen [Adw]
ClamAVWin.Malware.Agent-6369865-0
GDataGen:Variant.Adware.Graftor.290828
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.bpd
AlibabaAdWare:Win32/Kuaiba.1dd5e0d8
NANO-AntivirusRiskware.Win32.Kuaiba.esyjzv
ViRobotAdware.Kuaiba.1721848
AegisLabAdware.Win32.Kuaiba.2!c
APEXMalicious
Ad-AwareGen:Variant.Adware.Graftor.290828
SophosGeneric PUA PP (PUA)
ComodoApplicUnwnt@#a49tfbe7qgww
F-SecureAdware.ADWARE/Kuaiba.ygcus
DrWebTrojan.DownLoader25.38574
ZillyaAdware.KuaibaCRTD.Win32.960
Invinceaheuristic
McAfee-GW-EditionGenericRXES-JZ!C9A2B6EB0BAD
EmsisoftGen:Variant.Adware.Graftor.290828 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Adware.DHPJ-4181
JiangminAdWare.Kuaiba.bf
WebrootW32.Adware.Gen
AviraADWARE/Kuaiba.ygcus
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.BTSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Adware.Graftor.D4700C
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.bpd
MicrosoftPUA:Win32/Kuaiba
McAfeeGenericRXES-JZ!C9A2B6EB0BAD
VBA32Trojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Kuaiba.L
RisingMalware.Generic.5!tfe (CLOUD)
YandexPUA.Kuaiba!
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Kuaiba
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.11379019.susgen

How to remove Adware.Graftor.290828 (B)?

Adware.Graftor.290828 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment