Malware

Fugrafa.2003 removal

Malware Removal

The Fugrafa.2003 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.2003 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

lxixa9.no-ip.biz

How to determine Fugrafa.2003?


File Info:

crc32: DDE10E8D
md5: ac342791c6be7fbffaaf3da7ea39b0fc
name: AC342791C6BE7FBFFAAF3DA7EA39B0FC.mlw
sha1: 66e606bad7aaebce67f31a640b8140ca96cb99de
sha256: 15b45bc0c4dc4982f67d3838c1b3f903080cf82b7949ebf06f7286a5b8679f83
sha512: d2541418e193d28f27bbe7512850e254a26cf63d1621ac06d1962ec6cc97aa00353faf81c56f9c38430bf8696b9d8fad5b39079426ee9293ed8254a9860497e2
ssdeep: 12288:TQZMWMsbfGUrjSUDGczfBEPLqDdKR7ORx2969cYJf/m4WyC6:UeHmHnaPLodGToj
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Fugrafa.2003 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.2003
FireEyeGeneric.mg.ac342791c6be7fbf
CAT-QuickHealTrojan.Ircbrute.AZ6
McAfeeW32/IRCBot.gen.bs
MalwarebytesGeneric.Trojan.Dropper.DDS
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005325bc1 )
BitDefenderGen:Variant.Fugrafa.2003
K7GWTrojan ( 005325bc1 )
Cybereasonmalicious.1c6be7
BaiduWin32.Trojan.Injector.js
CyrenW32/Agent.KL.gen!Eldorado
SymantecW32.IRCBot
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyWorm.Win32.Ngrbot.dhx
NANO-AntivirusTrojan.Win32.Ruskill.qohco
ViRobotWorm.Win32.A.Ngrbot.81686
RisingBackdoor.Win32.Fednu.qw (CLASSIC)
Ad-AwareGen:Variant.Fugrafa.2003
EmsisoftGen:Variant.Fugrafa.2003 (B)
ComodoTrojWare.Win32.Injector.hhv@4ay6dr
DrWebBackDoor.IRC.Bot.3127
ZillyaBackdoor.Ruskill.Win32.94
McAfee-GW-EditionBehavesLike.Win32.IRCBot.gc
SophosML/PE-A + Mal/Inject-CEE
IkarusBackdoor.Poison
JiangminBackdoor/Ruskill.bf
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.Ngrbot
MicrosoftWorm:Win32/Ainslot
ArcabitTrojan.Fugrafa.D7D3
ZoneAlarmWorm.Win32.Ngrbot.dhx
GDataGen:Variant.Fugrafa.2003
TACHYONWorm/W32.NgrBot.502336
AhnLab-V3Trojan/Win32.CSon.R6141
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.EyX@aucFOWnG
ALYacGen:Variant.Fugrafa.2003
MAXmalware (ai score=84)
VBA32BScope.Trojan-Injector.23805
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.HDS
TrendMicro-HouseCallHT_NGRBOT_GC16012C.UVPM
TencentMalware.Win32.Gencirc.10b77a8f
YandexBackdoor.Ruskill!TTWXv50Itsg
SentinelOneStatic AI – Malicious PE – Worm
FortinetW32/Injector.KSK!tr
AVGWin32:Dorkbot-BH [Trj]
AvastWin32:Dorkbot-BH [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Bgrbot.A

How to remove Fugrafa.2003?

Fugrafa.2003 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment