Malware

Graftor.108094 removal instruction

Malware Removal

The Graftor.108094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.108094 virus can do?

  • Executable code extraction
  • Injection with SetWindowLong in a remote process
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Injected into Explorer using shared memory and window message technique
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Graftor.108094?


File Info:

crc32: 382C2601
md5: 3840a04a11272d9c4176113f3e5afeae
name: 3840A04A11272D9C4176113F3E5AFEAE.mlw
sha1: 17ea9e51a4c03ea29e356ba8336ccf3383d75fcd
sha256: 34d329c07c60ffee018ab7a9d0131f602c51dc9de54da375dc383156e3881d3d
sha512: 8e5b3e6bf4ef539f47fe921c0af4d6b485c6862b818416e19a52877409dcd5d94a0befcb2a85af59b2e5aa6223f0cf4127790df7973cdb0aeddc993eb6f63cd2
ssdeep: 3072:D4stjb+NKFwADNqvXGsxWgMJqBkYHAF5UDoqi8gp6mzathtDdBU1DPV8CU0Wc:sshb+dAwDxWgMJqBkODpiZEHthtDs1D
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: License: MPL 2
InternalName:
FileVersion: 21.0
CompanyName: Mozilla Foundation
BuildID: 20130511120803
LegalTrademarks: Mozilla
Comments:
ProductName: Firefox
ProductVersion: 21.0
FileDescription: Firefox Software
OriginalFilename: u.exe
Translation: 0x0000 0x04b0

Graftor.108094 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader10.5367
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.108094
CylanceUnsafe
SangforSuspicious.Win32.Evo.atgen
AlibabaTrojan:Win32/Kryptik.46ccf974
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.a11272
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BHDR
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.108094
NANO-AntivirusTrojan.Win32.Sharik.cbclfm
MicroWorld-eScanGen:Variant.Graftor.108094
TencentWin32.Trojan.Sharik.Ljka
Ad-AwareGen:Variant.Graftor.108094
ComodoMalware@#2nhyjsmsl0sde
BitDefenderThetaGen:NN.ZexaF.34170.lmKfayRaOfci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.emy
FireEyeGeneric.mg.3840a04a11272d9c
EmsisoftGen:Variant.Graftor.108094 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1110410
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.108094
AhnLab-V3Trojan/Win32.Sharik.R78579
McAfeeGeneric.emy
MAXmalware (ai score=99)
VBA32Trojan.Yakes
PandaTrj/CI.A
YandexTrojan.GenAsa!dNomXfBvmh0
IkarusTrojan.Win32.Sharik
FortinetW32/Sharik.PIY!tr
AVGWin32:Rootkit-gen [Rtk]

How to remove Graftor.108094?

Graftor.108094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment