Adware

What is “Adware.Graftor.46075”?

Malware Removal

The Adware.Graftor.46075 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.46075 virus can do?

  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Graftor.46075?


File Info:

name: B999CA090824161E5CFE.mlw
path: /opt/CAPEv2/storage/binaries/f45e00738230160510d482450388dfdf44f646320838bb0b723638dd372642f0
crc32: A9A5D9A2
md5: b999ca090824161e5cfe2ff5f73ea058
sha1: 830b0116cfa68cb3887d5e41814585e8f18d21df
sha256: f45e00738230160510d482450388dfdf44f646320838bb0b723638dd372642f0
sha512: 1257883e78a552c35f60c063b4633e3686f5eda19caef0524c23a252776a8ed88e468b4c5efe41d39e81ad6f839c1bb1bb4845a0ef9f93fdad31cf4fa4e22fe4
ssdeep: 6144:EQg6R6F9j4z7WHf09RbMOs02+NfOV9ddrFm6UvjaEo+8NfWxU5s1nqSZK3LR:Jg6ZzS89qODdG9ddrILrCfWxwp3LR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11274F15367F64948F6F6A7705DBB06940A29FC9AB976CD0D2010D98E2EB0F40DCA2773
sha3_384: 923ddbec281417c1f3d5814083bdd664cdeebfaf341985e185fc97c686112bd72385dbb268eba376ffffe83b51062b98
ep_bytes: 60be002048008dbe00f0f7ff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Adware.Graftor.46075 also known as:

BkavW32.Common.3BBE70AE
LionicAdware.Win32.ForceStartPage.2!c
Elasticmalicious (moderate confidence)
DrWebAdware.Downware.335
MicroWorld-eScanGen:Variant.Adware.Graftor.46075
FireEyeGeneric.mg.b999ca090824161e
CAT-QuickHealHackTool.Injectxin.A8
ALYacGen:Variant.Adware.Graftor.46075
MalwarebytesGeneric.Malware.AI.DDS
ZillyaAdware.ForceStartPage.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003bb3161 )
AlibabaAdWare:Win32/ForceStartPage.bcfcbfeb
K7GWTrojan ( 003bb3161 )
BitDefenderThetaGen:NN.ZelphiF.36804.wmGfa48tm9oc
VirITAdware.Generic5.FUD
SymantecSMG.Heur!gen
ESET-NOD32Win32/DownloadGuru potentially unwanted
APEXMalicious
TrendMicro-HouseCallTSPY_AGENT_BK080382.TOMC
AvastWin32:PUP-gen [PUP]
ClamAVWin.Trojan.653825-1
Kasperskynot-a-virus:AdWare.Win32.ForceStartPage.a
BitDefenderGen:Variant.Adware.Graftor.46075
NANO-AntivirusTrojan.Win32.Downware2.bbxdmy
SUPERAntiSpywareTrojan.Agent/Gen-StartPage
RisingTrojan.Win32.Generic.12DBAAC2 (C64:YzY0OmYV434yv3/z)
EmsisoftGen:Variant.Adware.Graftor.46075 (B)
F-SecureTrojan.TR/StartPage.879411
BaiduWin32.Adware.Generic.v
VIPREGen:Variant.Adware.Graftor.46075
TrendMicroTSPY_AGENT_BK080382.TOMC
Trapminemalicious.moderate.ml.score
SophosDownload-Guru (PUA)
Ikarusnot-a-virus:AdWare.Win32.ForceStartPage
JiangminAdware.Agent.aizm
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/StartPage.879411
VaristW32/ForceStart.SRDH-1174
Antiy-AVLGrayWare[AdWare]/Win32.ForceStartPage
Kingsoftmalware.kb.b.865
MicrosoftAdware:Win32/Multiverze
XcitiumTrojWare.Win32.Agent.RKD@4pmhfc
ArcabitTrojan.Adware.Graftor.DB3FB
ViRobotAdware.Forcestartpage.364032.CRU
ZoneAlarmnot-a-virus:AdWare.Win32.ForceStartPage.a
GDataGen:Variant.Adware.Graftor.46075
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.Strictor.R28839
VBA32BScope.Adware.ForceStartPage
Cylanceunsafe
PandaTrj/Genetic.gen
TencentAdware.Win32.ForceStartpage.a
YandexTrojan.GenAsa!v6IBKgi1Ac8
MAXmalware (ai score=99)
MaxSecureTrojan.Malware.8325621.susgen
FortinetRiskware/DownloadGuru
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/ForceStartPage.a

How to remove Adware.Graftor.46075?

Adware.Graftor.46075 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment