Malware

Fugrafa.102068 information

Malware Removal

The Fugrafa.102068 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.102068 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.102068?


File Info:

crc32: 99C95D13
md5: b0212d7de75cfffdf307a285dd55c010
name: B0212D7DE75CFFFDF307A285DD55C010.mlw
sha1: 9ff1f165b230230a876947dfba197429c9bfa7df
sha256: ac3a64a2c5bbdbaa1d2a1d78a667a718c31b79e7699c2db862c258dfb57bd3d6
sha512: 4acb16532985701abb86b34db1815be36a73a00a917d7068233170f4ad8440e1d87ef2f28218cae2497ffc368b207d9ef697e2be173d6bee7d94ae88a7d91f1f
ssdeep: 3072:biJFi4Tixa0RRfKU2jquB2RtgEEFVNFAr/FcMsf5pIO2YaKewBRCkrZuq7KL+iH:u7+xNth2jqhRtsCtcTfsO/bC+8qGCik
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Unspurious
InternalName: blebs
FileVersion: 8.9
CompanyName: Unspurious
ProductName: blebs tivy ony muir
ProductVersion: 8.9
FileDescription: blebs deems
OriginalFilename: blebs.exe
Translation: 0x0409 0x04b0

Fugrafa.102068 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051c8c91 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.102068
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Zerber.e511c4af
K7GWTrojan ( 0051c8c91 )
Cybereasonmalicious.de75cf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYIY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fikg
BitDefenderGen:Variant.Fugrafa.102068
NANO-AntivirusTrojan.Win32.Zerber.evnccq
MicroWorld-eScanGen:Variant.Fugrafa.102068
TencentWin32.Trojan.Zerber.Pben
Ad-AwareGen:Variant.Fugrafa.102068
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#31zyp932ma59a
BitDefenderThetaAI:Packer.7CE0ABC721
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.b0212d7de75cfffd
EmsisoftGen:Variant.Fugrafa.102068 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1121407
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber.B
ArcabitTrojan.Fugrafa.D18EB4
ZoneAlarmTrojan-Ransom.Win32.Zerber.fikg
GDataGen:Variant.Fugrafa.102068
Acronissuspicious
McAfeeArtemis!B0212D7DE75C
MAXmalware (ai score=96)
VBA32BScope.TrojanRansom.Zerber
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDML:SUiSlhVcIxpuzfAl6J3dHQ)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Fugrafa.102068?

Fugrafa.102068 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment