Adware

Adware.Graftor.290828 removal instruction

Malware Removal

The Adware.Graftor.290828 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.290828 virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz
query.run456.com
stat.run456.com

How to determine Adware.Graftor.290828?


File Info:

crc32: 13FAEC76
md5: 636403c0bab70c5e196d8ac598fb6d2f
name: Gamestart.exe
sha1: 1d4df6876fdc5d2b53d4a0f1cc50aca4a87bf28a
sha256: 3f1110e1f78ff2f1a983ad893d3c7838da8048485d3af97e7d068433d0705359
sha512: b8f3b3d4f3b7d7f1c0675c9dc48790ef8005ffd9e7819b363651585f3fa4b12f4eadd4c616e8ff0f2b667d691cdf68baaced1e60e7589c4ab587b12083dfb8a6
ssdeep: 24576:XgK5mTqk8oIWwHZSlioOKKhuwx0gPTvufUbZ1YOtLlqfUY/48jRT+JLlkESmiyCc:wzc1Lpuwx0mZGMEUY/48jRTqL2ESnW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: x6e38x620fx5b89x88c5x7a0bx5e8f
FileVersion: 2.3.0.302
ProductName: x6e38x620fx5b89x88c5x7a0bx5e8f
ProductVersion: 2.3.0.302
FileDescription: x6e38x620fx5b89x88c5x7a0bx5e8f
OriginalFilename: setup.exe
Translation: 0x0804 0x04b0

Adware.Graftor.290828 also known as:

MicroWorld-eScanGen:Variant.Adware.Graftor.290828
FireEyeGeneric.mg.636403c0bab70c5e
McAfeePUP-XIS-AF
ALYacGen:Variant.Adware.Graftor.290828
CylanceUnsafe
VIPREAdware.Win32.Kuaiba
SangforMalware
K7AntiVirusAdware ( 005524301 )
BitDefenderGen:Variant.Adware.Graftor.290828
K7GWAdware ( 005524301 )
Cybereasonmalicious.0bab70
TrendMicroTROJ_GEN.R002C0PJ119
SymantecTrojan.Gen.2
Paloaltogeneric.ml
GDataGen:Variant.Adware.Graftor.290828
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.bqd
AlibabaAdWare:Win32/Kuaiba.1e4211a8
NANO-AntivirusRiskware.Win32.Kuaiba.etpotu
ViRobotAdware.Kuaiba.1703832
AegisLabAdware.Win32.Kuaiba.2!c
AvastWin32:Adware-gen [Adw]
RisingTrojan.Generic@ML.80 (RDMK:J/7xWtXVVRCBawIC2SZGEg)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Adware.Graftor.290828 (B)
ComodoApplicUnwnt@#36d6eaq70xnd6
F-SecureAdware.ADWARE/Kuaiba.hswfo
DrWebTrojan.DownLoader25.46822
ZillyaAdware.KuaibaCRTD.Win32.960
Invinceaheuristic
McAfee-GW-EditionPUP-XIS-AF
SophosGeneric PUA BN (PUA)
IkarusPUA.Kuaiba
JiangminAdWare.Kuaiba.be
WebrootW32.Adware.Gen
AviraADWARE/Kuaiba.hswfo
MAXmalware (ai score=99)
Antiy-AVLGrayWare[AdWare]/Win32.Kuaiba
ArcabitTrojan.Adware.Graftor.D4700C
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.bqd
MicrosoftPUA:Win32/Kuaiba
AhnLab-V3PUP/Win32.Generic.R236026
VBA32AdWare.Kuaiba
Ad-AwareGen:Variant.Adware.Graftor.290828
ESET-NOD32a variant of Win32/Adware.Kuaiba.G
TrendMicro-HouseCallTROJ_GEN.R002C0PJ119
TencentMalware.Win32.Gencirc.10b2b97e
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Kuaiba
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Adware.Graftor.290828?

Adware.Graftor.290828 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment