Adware

Adware.Graftor.Elzob.23165 removal instruction

Malware Removal

The Adware.Graftor.Elzob.23165 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor.Elzob.23165 virus can do?

  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Adware.Graftor.Elzob.23165?


File Info:

name: 58BE90F989FB05004F05.mlw
path: /opt/CAPEv2/storage/binaries/0656a42c513fcedb2d031f7e833398c9d0bde977b3de04f0c6a325c705086ecd
crc32: DAD0CE71
md5: 58be90f989fb05004f0559b5f7751607
sha1: 016a2db838e6303822bd6f4e70b1e46e64bec4fd
sha256: 0656a42c513fcedb2d031f7e833398c9d0bde977b3de04f0c6a325c705086ecd
sha512: 8b7924b9ef88f12cf7fa6a06cfbeed32f6036a70ee4fd27079212b9d6cf54bbdad80ca58f4e999325c1f5a0960fc2d343c31963fb45c0486791ac1927ec151e9
ssdeep: 12288:ipnuSn0wPMCvJ9umxxe07Ion+CwTD1iSXU9GENWl/e7lWoFJ3VBEGQgBn:iwcMCvJwQxp+tT4SXU9GvEZr3wC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138356C22F2815837D1633AF89C6BA659542ABE542D385D0A3AF83D4C4E35783FC3529F
sha3_384: 479cf49c6fcd1d87d8e1d3819ef2ff57741dcd0c0a2cdd65c81cd4a1d46e32809430ff74528b816ec59e1b84cbce0c47
ep_bytes: 558bec83c4f0b898b74c00e894abf3ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Adware.Graftor.Elzob.23165 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Tibia.2206
MicroWorld-eScanGen:Variant.Adware.Graftor.Elzob.23165
FireEyeGeneric.mg.58be90f989fb0500
McAfeeGenericRXAA-AA!58BE90F989FB
CylanceUnsafe
ZillyaTrojan.Delf.Win32.45986
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.989fb0
VirITTrojan.Win32.Generic.BWTY
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Filenolja.A
ClamAVWin.Trojan.Delf-28416
Kasperskynot-a-virus:Downloader.Win32.Filenolja.br
BitDefenderGen:Variant.Adware.Graftor.Elzob.23165
NANO-AntivirusTrojan.Win32.Tibia.dknpvj
AvastWin32:PUP-gen [PUP]
TencentMalware.Win32.Gencirc.10b4412f
Ad-AwareGen:Variant.Adware.Graftor.Elzob.23165
SophosGeneric PUA AB (PUA)
ComodoApplicUnwnt.Win32.AdWare.Delf.FN@4p6ycn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Adware.Graftor.Elzob.23165 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PSW.Delf.fer
Webroot
AviraADWARE/Adware.ZM.2
MAXmalware (ai score=69)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Adware.Graftor.Elzob.23165
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.FileNolja.R23303
VBA32TScope.Trojan.Delf
APEXMalicious
RisingAdware.Filenolja!1.C074 (CLASSIC)
YandexTrojan.GenAsa!Sw5WlV1/OrE
IkarusTrojan-GameThief.Win32.Tibia
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.AOU!tr.dldr
AVGWin32:PUP-gen [PUP]

How to remove Adware.Graftor.Elzob.23165?

Adware.Graftor.Elzob.23165 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment