Malware

Graftor.104958 removal instruction

Malware Removal

The Graftor.104958 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.104958 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Graftor.104958?


File Info:

crc32: DB19A653
md5: ec8a5999d4f921d3df8d6deadd0acc3e
name: EC8A5999D4F921D3DF8D6DEADD0ACC3E.mlw
sha1: fb962aea42a32073601255ef2b589a9e4fd0d1d2
sha256: 6bb8fa02fae6b4cea1c67d2280edfc66d74e63515b72bc0f99ed79d9aeab7f9e
sha512: ae8716aca5a728ae26e42ebdb8aa193d746a68abbd46814ae1b6b50df035c706703d977838ec38ed6e5fc8f8dc568581591e4fcaa61cd3cf90f4f2ea2f3e03e2
ssdeep: 49152:AvGRVQHt8UbRMaRU1ggzzLQ/YsvD/DX+y4onCYDoD5:EN88MaeggzzLQ/YsvD/D+donCYUV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.104958 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLP.ZloyFly.2
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Zegost.BZ4
ALYacGen:Variant.Graftor.104958
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.9d4f92
BaiduWin32.Trojan.Farfli.ai
CyrenW32/Autorun.CKVB-8929
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Vjadtre-6840658-0
KasperskyTrojan-Dropper.Win32.Flystud.d
BitDefenderGen:Variant.Graftor.104958
NANO-AntivirusRiskware.Win32.FlyStudio.dhaj
ViRobotWin32.FlyStud.A
MicroWorld-eScanGen:Variant.Graftor.104958
TencentTrojan.Win32.Flystud.a
Ad-AwareGen:Variant.Graftor.104958
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.Agent.~JJB@1ibpfm
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.tc
FireEyeGeneric.mg.ec8a5999d4f921d3
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Flystud.btu
AviraTR/Dropper.Gen
eGambitTrojan.Generic
MicrosoftDDoS:Win32/Nitol.B
GridinsoftMalware.Win32.Gen.sm!s1
ArcabitTrojan.Graftor.D199FE
GDataWin32.Trojan.FlyStudio.A
AhnLab-V3Dropper/Flystud.1490549
Acronissuspicious
McAfeeMultiDropper-TI
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Zegost
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
RisingDropper.Agent.wh (CLASSIC)
IkarusTrojan.Win32.FlyStudio
MaxSecureTrojan.Autorun.DM
FortinetW32/Generic.AP.14793D8!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM07.1.A922.Trojan-Dropper.Win32.Flystud

How to remove Graftor.104958?

Graftor.104958 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment