Adware

How to remove “Adware.Graftor”?

Malware Removal

The Adware.Graftor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Graftor virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Adware.Graftor?


File Info:

name: E8E432F55CC48FE3F431.mlw
path: /opt/CAPEv2/storage/binaries/9affe7dc19f4ed3b87d8a51116cda97718da8586c88a863032c4203e5bceb061
crc32: 69053F23
md5: e8e432f55cc48fe3f431ef58a9660ede
sha1: 338c08134b2840d4346f4410c4c711b2cda5a7e0
sha256: 9affe7dc19f4ed3b87d8a51116cda97718da8586c88a863032c4203e5bceb061
sha512: c7d658f0ead2c3800000cdfe3f6b65b103626f58fa49b357ac207196b1aabb70229220131c952ba13d482b67a4e1ba3fbfbc19b82864897ed7062b2fd4c13dd6
ssdeep: 12288:7SADDHyj7/BbmaDEPoiAtPA6lHu1PUK1FpXScTbNNwzwBJwBarsGSjl:Hy9EAZI6lK1FpzTBKzGJGayl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC056B51B481C034F9BD01BC02E99777262B6A12571AD6E377AC5D0A3B201FE7EF4A36
sha3_384: 55b5d1215a05e152525c2f73f083ade8dae2956f4f343a2c6ffe457cd34fdf349c1de99e992886c59081c3e6d4a70a06
ep_bytes: e8a7d10000e9000000006a1468b85348
timestamp: 1970-01-01 05:47:14

Version Info:

FileVersion: 1.5.6.2919
ProductVersion: 15, 6.29
Translation: 0x0804 0x04b0

Adware.Graftor also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.306696
FireEyeGeneric.mg.e8e432f55cc48fe3
CAT-QuickHealTrojan.Skeeyah.17537
McAfeeTrojan-FHGH!E8E432F55CC4
CylanceUnsafe
ZillyaAdware.BHO.Win32.7751
K7AntiVirusAdware ( 004c75cb1 )
BitDefenderGen:Variant.Zusy.306696
K7GWAdware ( 004c75cb1 )
Cybereasonmalicious.55cc48
BaiduWin32.Trojan.Agent.aau
VirITTrojan.Win32.Generic.BWKL
CyrenW32/Horst.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.BHO.NLN
APEXMalicious
ClamAVWin.Malware.Jaik-9660700-0
KasperskyTrojan.Win32.Agent.iguu
NANO-AntivirusTrojan.Win32.Crypted.dtlasb
RisingAdWare.Win32.BHO.fkg (RDMK:cmRtazpfRZ/hq6facjnhQjO9Zqw7)
EmsisoftGen:Variant.Zusy.306696 (B)
ComodoApplication.Win32.AdWare.BHO.AD@5t6i8s
DrWebTrojan.Siggen6.45515
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
SophosAdWin (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agentb.bpk
WebrootW32.Adware.Gen
AviraTR/Kryptik.qgmpa
Antiy-AVLTrojan/Generic.ASMalwS.1171445
MicrosoftTrojan:Win32/Dorv.A
ZoneAlarmTrojan.Win32.Agent.iguu
GDataGen:Variant.Zusy.306696
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnLineGames.R156869
BitDefenderThetaGen:NN.ZexaF.34182.Yq0@aOQUSQej
ALYacGen:Variant.Zusy.306696
MAXmalware (ai score=89)
VBA32BScope.Trojan.KillFiles
MalwarebytesAdware.Graftor
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b08034
IkarusTrojan.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.IGUU!tr
AVGWin32:GenMaliciousA-QKI [Trj]
AvastWin32:GenMaliciousA-QKI [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.Graftor?

Adware.Graftor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment