Malware

Fugrafa.255977 (B) removal guide

Malware Removal

The Fugrafa.255977 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.255977 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality

How to determine Fugrafa.255977 (B)?


File Info:

name: 95A3F0DA535C2C4D44E9.mlw
path: /opt/CAPEv2/storage/binaries/e9d28863baf2a58db238f3fed8c6a4e5be2e0cfdc044a769a1f01573609a21d1
crc32: A634A311
md5: 95a3f0da535c2c4d44e9d7b7379e9a18
sha1: d707e930e082536ca1253c852c9fd8d1d1973350
sha256: e9d28863baf2a58db238f3fed8c6a4e5be2e0cfdc044a769a1f01573609a21d1
sha512: 4764fe1dfe2e1a06c4c496437a082c74abb1faff298c5b80b236a99452d66e3818768510b15904bcc62c9b6d99f558c935427c3d1a60bb18b55bbcf7e13e9c3a
ssdeep: 384:UW3nWdUx9K09RXjXz7XjCWwqK8Wzz8WW5bIwHhm9qBhRJ3vFzeTV9idpXhIHvDmt:r3nLbZ9xjXvKBBW5bhmIB3hvFzen7lm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T164C2AFDFF0818C31DAA072FA54B26AB8C7FE7830F634B8218A74D7091957450E70679A
sha3_384: 52b1513fc8c6f3360a9936370a2ef9b849f5e68eff42152cb0ced8336bf6e85fa14d7fbba752e4a2072c1319b092819d
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.255977 (B) also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fugrafa.255977
ALYacGen:Variant.Fugrafa.255977
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.a535c2
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fugrafa.255977
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fugrafa.255977
EmsisoftGen:Variant.Fugrafa.255977 (B)
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!95A3F0DA535C
FireEyeGeneric.mg.95a3f0da535c2c4d
SophosML/PE-A + Troj/PWS-CMJ
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Fugrafa.D3E7E9
GDataGen:Variant.Fugrafa.255977
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Reputation.C4266831
Acronissuspicious
McAfeeGenericRXNV-VM!95A3F0DA535C
MAXmalware (ai score=85)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.5437263.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fugrafa.255977 (B)?

Fugrafa.255977 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment