Malware

Graftor.298508 removal instruction

Malware Removal

The Graftor.298508 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.298508 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known MarsJoke ransomware decryption instruction / key file.
  • Collects information to fingerprint the system

How to determine Graftor.298508?


File Info:

crc32: 7B46ABFD
md5: 87f8b0ac798135752cd18f20e6bf5976
name: 87F8B0AC798135752CD18F20E6BF5976.mlw
sha1: 344c69e59afa4aabf6bc55a3933c94d587df9b7f
sha256: c4882bcf09ce1a0be7db6b09984cce19926d03df104c5b8e631d08caa3d2c0de
sha512: 2ba26d3698c3c50115614c2078f8e7c07805364d95945f29de00aa57b0f2b8408a20e196074a71a22f84f6720fd9a8adbf9d6848d27050f7f651db8f4c6a10a7
ssdeep: 12288:xfGVwGAK/2+/4YNQ5Kb4gGRnW/8SK65CiMTPLzEPQNYksxo+:xfG2GAk2+JNQ85GRnW/rKPTTJc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: sysmonitor.exe
FileVersion: 1.0.0.1
CompanyName: Microsoft
ProductName:
ProductVersion: 1.0.0.1
FileDescription: System monitor
OriginalFilename: sysmonitor.exe
Translation: 0x0409 0x04e4

Graftor.298508 also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
DrWebTrojan.Encoder.5704
ALYacGen:Variant.Graftor.298508
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3026
AlibabaRansom:Win32/MarsJoke.ali1020008
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.c79813
SymantecRansom.MarsJoke
ESET-NOD32Win32/Filecoder.NHO
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.298508
NANO-AntivirusTrojan.Win32.TrjGen.efmyrf
MicroWorld-eScanGen:Variant.Graftor.298508
TencentMalware.Win32.Gencirc.114bb2f1
Ad-AwareGen:Variant.Graftor.298508
SophosMal/Generic-R + Troj/Ransom-DUO
BitDefenderThetaGen:NN.ZexaF.34058.Kq0@am9tMOdk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.ags
FireEyeGen:Variant.Graftor.298508
EmsisoftGen:Variant.Graftor.298508 (B)
JiangminWorm.Generic.ccs
WebrootTrojan.Ransom.Jokemars.A
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Polyglot.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.298508
TACHYONRansom/W32.MarsJoke.593920
AhnLab-V3Malware/Win32.Ransom_.C1586364
McAfeeGeneric.ags
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Polyglot
PandaTrj/GdSda.A
YandexTrojan.GenAsa!U8CSt8jkwMI
IkarusWorm.Genun
FortinetW32/Generic.AP.FBF40A!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Generic.HwkA1rkA

How to remove Graftor.298508?

Graftor.298508 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment