Malware

Should I remove “Fugrafa.256140”?

Malware Removal

The Fugrafa.256140 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.256140 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Fugrafa.256140?


File Info:

name: FD5B1E8A0513EC770DBD.mlw
path: /opt/CAPEv2/storage/binaries/89ef34a94ff9036a8d87ce9fc8ebbd3a076fc43bb60feab1da811ccf8f672adb
crc32: 70FB1D27
md5: fd5b1e8a0513ec770dbdc872ff6f7929
sha1: 84c1e79a2e3f00216acbdf237455d63a709dec0a
sha256: 89ef34a94ff9036a8d87ce9fc8ebbd3a076fc43bb60feab1da811ccf8f672adb
sha512: eca9b3f1e285cbc8b72611c470b70276f440c62ef89117d53be5a2a72c634c8a9683f56ce458d4c5e7345fd5f3b388721d707281155522167ecfe9d164d8b1e4
ssdeep: 384:FWjjKuUx99P09RXjXz7XjCWwqK8Wzz8WW5bIwHLTOC+Cehcf1M7ocBAD4GK+SkqM:sjjAb9c9xjXvKBBW5bLTLTf1MtaSFM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BAC2AF93BAB088B5DFA00471127169F683FF7C30FB19E6625B21E91D06B5857DE0E18B
sha3_384: 181bd524ad1f416bd3cb46d1fe5177cae843ec9acfdecd6f944710ab77fdd7a374ac58acfd88ea545ee84e161ce01484
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.256140 also known as:

MicroWorld-eScanGen:Variant.Fugrafa.256140
ALYacGen:Variant.Fugrafa.256140
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.a0513e
CyrenW32/Agent.ENB.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fugrafa.256140
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fugrafa.256140
EmsisoftGen:Variant.Fugrafa.256140 (B)
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!FD5B1E8A0513
FireEyeGeneric.mg.fd5b1e8a0513ec77
SophosML/PE-A + Troj/PWS-CMJ
IkarusTrojan.DelFiles
GDataGen:Variant.Fugrafa.256140
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
ArcabitTrojan.Fugrafa.D3E88C
MicrosoftTrojanDownloader:Win32/Emotet!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
McAfeeGenericRXNV-VM!FD5B1E8A0513
MAXmalware (ai score=88)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
MaxSecureTrojan.Malware.5437263.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fugrafa.256140?

Fugrafa.256140 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment