Malware

Should I remove “Fugrafa.204986”?

Malware Removal

The Fugrafa.204986 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.204986 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.204986?


File Info:

name: F77A50B4F37D8B1D3763.mlw
path: /opt/CAPEv2/storage/binaries/4c755d6b4ad8fa0c14f8a1bc0f0694e163396f7e649d7e1c9a43214e2ff1b9df
crc32: F3C6F879
md5: f77a50b4f37d8b1d37637beef6048fd9
sha1: 0046c8c9c3e826eb63af162a78acf046aaaf769d
sha256: 4c755d6b4ad8fa0c14f8a1bc0f0694e163396f7e649d7e1c9a43214e2ff1b9df
sha512: fe0fbd28f0934f412bc64ee754ad2b0400220d59ceea58ff78d8e77c00c99ef202b80da2ad527fa9245588490d283e610501b2c6b2389fa93c0445a8c3cb8258
ssdeep: 49152:JTjXSfuuzu6HJRl7CrGvhP+uJtbQFRqMkSuvLokkfLohvko4d9a63M:JTjou6rzCS4u7bpMkSuvXwLsYxM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141B52321B9C489B2E5B3093519F84B70A76C3D111B29DBDF9318B72D5E34AC18A35BE3
sha3_384: 217412427a97f2255576b71629aa422815efccd5018079a929c25134e00bdfb8ea2dfc8ae1ce82c8a331db62c26297f6
ep_bytes: e815060000e978feffffe9cf3c000055
timestamp: 2021-10-10 18:54:40

Version Info:

0: [No Data]

Fugrafa.204986 also known as:

MicroWorld-eScanGen:Variant.Fugrafa.204986
FireEyeGeneric.mg.f77a50b4f37d8b1d
McAfeeArtemis!F77A50B4F37D
ZillyaTrojan.Qshell.Win32.585
ESET-NOD32RAR/Agent.DQ
APEXMalicious
KasperskyUDS:Trojan.Win32.Cryprar.gen
BitDefenderGen:Variant.Fugrafa.204986
AvastFileRepMalware
Ad-AwareGen:Variant.Fugrafa.204986
EmsisoftGen:Variant.Fugrafa.204986 (B)
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fugrafa.204986
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.204986
MAXmalware (ai score=82)
VBA32BScope.Trojan.Meterpreter
ZonerProbably Heur.RARAutorun
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
AVGFileRepMalware
Cybereasonmalicious.9c3e82

How to remove Fugrafa.204986?

Fugrafa.204986 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment