Malware

Graftor.250958 removal tips

Malware Removal

The Graftor.250958 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.250958 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Graftor.250958?


File Info:

name: 4778DA9F9220A5D460CA.mlw
path: /opt/CAPEv2/storage/binaries/2737989e54cf6e6f42dc9c01a05ce942bbf6efef3246fa2a873b345c4ac65b65
crc32: 3DAF04E0
md5: 4778da9f9220a5d460ca71067e3f82c2
sha1: 8e63257616ac01aa4b3a6ac981f17bb1a4e42717
sha256: 2737989e54cf6e6f42dc9c01a05ce942bbf6efef3246fa2a873b345c4ac65b65
sha512: 4e8eaf4d4418e5854d5e3ef37a0df6893959d23df66d2a5be8ab7f46dc8eca443903e6d642d0fcf71d1dc9291dddce7c8983adee702a093ac9387aba61e8a4aa
ssdeep: 1536:ry3z/UYZBovl6zFVbmC+bUBzun5kS1fcCKbJbwwQe:r01VJ0gC5/dKbZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A83B1D6E676CCD2D5090C70C1D932F24FAA4FAFE191710BBB38BE2974B269704148B9
sha3_384: c5ff0feff0ac404e42893e18d51f2de5da0b292ba2998df8e571106e0169ca7c002302886aa9e7c1d9047de8eca8c96e
ep_bytes: 558bec6aff68f8534000687c43400064
timestamp: 2015-09-30 17:20:07

Version Info:

0: [No Data]

Graftor.250958 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Turist.235
CynetMalicious (score: 99)
FireEyeGeneric.mg.4778da9f9220a5d4
CAT-QuickHealTrojan.Crowti.100411
McAfeeGeneric-FAWT!4778DA9F9220
CylanceUnsafe
ZillyaAdware.CrossRider.Win32.28997
K7AntiVirusTrojan ( 0055e3991 )
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.f9220a
BitDefenderThetaGen:NN.ZexaF.34182.fyY@aCUD5de
VirITTrojan.Win32.Inject3.IOK
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CKEI
APEXMalicious
ClamAVWin.Trojan.Agent-1349681
KasperskyTrojan.Win32.Inject.vjjk
BitDefenderGen:Variant.Graftor.250958
NANO-AntivirusTrojan.Win32.Cryptodef.dxsmtn
MicroWorld-eScanGen:Variant.Graftor.250958
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10c5bf65
EmsisoftGen:Variant.Graftor.250958 (B)
ComodoTrojWare.Win32.Inject.DVJ@5yiac5
VIPRETrojan.Win32.Waledac.tz (v)
TrendMicroTROJ_INJECT_EK0404CA.UVPM
McAfee-GW-EditionGeneric-FAWT!4778DA9F9220
SophosML/PE-A + Mal/Zbot-UE
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.tr
AviraHEUR/AGEN.1120607
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataGen:Variant.Graftor.250958
AhnLab-V3Trojan/Win32.CryptoWall.R165500
VBA32Trojan.Inject
ALYacGen:Variant.Graftor.250958
MAXmalware (ai score=83)
MalwarebytesRansom.CryptoWall
TrendMicro-HouseCallTROJ_INJECT_EK0404CA.UVPM
RisingMalware.Obscure/Heur!1.A89E (RDMK:cmRtazoKwgUtRtIqmh4QOCOzQl/K)
IkarusTrojan.Win32.Kelihos
FortinetW32/MFCkryp.CKEI!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Graftor.250958?

Graftor.250958 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment