Malware

Fugrafa.197763 removal

Malware Removal

The Fugrafa.197763 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.197763 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

How to determine Fugrafa.197763?


File Info:

name: ECEF70E3BBA87B2B98AC.mlw
path: /opt/CAPEv2/storage/binaries/7561724d98838751a552c50bebc70797102b4c522178cc1367b03cfd29b3b2f4
crc32: A94A7AE7
md5: ecef70e3bba87b2b98acc2b758553f2f
sha1: 96a470608e78cb020450124868ade90eba77b5d6
sha256: 7561724d98838751a552c50bebc70797102b4c522178cc1367b03cfd29b3b2f4
sha512: e0e2dc1eef970a6136161a5fb2a725e9c93ac8035af4c6475105953d3c7bfa3e7eec5273eff19c6fb40748e7eea8a8ac8e5a4193351ef4cee84d4c8b4c27af84
ssdeep: 12288:MLwoWUIqbKNZstadmfoBTglsS4bmAgIub1d+VG9+D9qFGBpYbe1upo1KqBr:qwRUIqbKNZstad2uTWb1d+VG0I5qB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T118E48D20B9C0C07BE57310321EACD6F516ADB8310BA515CBB3881BBA9F3D6D05B3665B
sha3_384: cc214dc47de63a060e0b90346769eb920c6efdf07352f0f897a7881de7d54715cc8211cad21e2f6b079e2bd7699097b9
ep_bytes: e8ca110000e929feffff8b4df464890d
timestamp: 2021-08-23 17:27:58

Version Info:

FileVersion: 1.0.0.0
LegalCopyright: All rights reserved
Translation: 0x0409 0x04b0

Fugrafa.197763 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.197763
ALYacGen:Variant.Fugrafa.197763
K7AntiVirusTrojan ( 005817351 )
K7GWTrojan ( 005817351 )
ArcabitTrojan.Fugrafa.D30483
CyrenW32/Agent.DJK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ADKJ
APEXMalicious
KasperskyVHO:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Fugrafa.197763
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10ced67c
Ad-AwareGen:Variant.Fugrafa.197763
EmsisoftGen:Variant.Fugrafa.197763 (B)
F-SecureHeuristic.HEUR/AGEN.1144103
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGen:Variant.Fugrafa.197763
IkarusTrojan.Win32.Agent
AviraHEUR/AGEN.1144103
Antiy-AVLTrojan/Generic.ASMalwS.347BB2F
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fugrafa.197763
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4608334
McAfeeGenericRXPM-EO!ECEF70E3BBA8
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Convagent
MalwarebytesSpyware.PasswordStealer
FortinetW32/Agent.ADKJ!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A

How to remove Fugrafa.197763?

Fugrafa.197763 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment