Malware

What is “Fugrafa.64902”?

Malware Removal

The Fugrafa.64902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.64902 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.64902?


File Info:

crc32: 087C8AE1
md5: a3181bf05308cb6ba6773cd80632fe8a
name: A3181BF05308CB6BA6773CD80632FE8A.mlw
sha1: 1bd3baef7282beb93d3301427eca8877d7229225
sha256: 5303ec7a342da994d9585a9c3eb8089d997a2edc7067eb7779e5680f9c5799a5
sha512: ef52b8a3aa122a61d44ac7a53933fd5377a49838398e02f14a7778292fe60c71513d610f05bb35f409837396dcfc8a97ec6875e334df7f1b50e67ad35c20fa9e
ssdeep: 6144:CUpJUwnej781t1VHp9B5ku1Mw+JVYF5UuEjWB8KmBLxBL:CkUwne78/VHnF1OJViEw+b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Piercers Fobs Rues
InternalName: demoted
FileVersion: 4.7.0.57112
CompanyName: Piercers Fobs Rues
ProductName: demoted credit cropped
ProductVersion: 4.7.0.57112
FileDescription: demoted pteroid
OriginalFilename: demoted.exe
Translation: 0x0409 0x04b0

Fugrafa.64902 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f27101 )
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.64902
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004f27101 )
Cybereasonmalicious.05308c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EZRH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fhun
BitDefenderGen:Variant.Fugrafa.64902
NANO-AntivirusTrojan.Win32.Zerber.evkpyb
MicroWorld-eScanGen:Variant.Fugrafa.64902
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Fugrafa.64902
SophosMal/Generic-S
ComodoMalware@#3rl636y7911tk
BitDefenderThetaGen:NN.ZexaF.34670.oi0@aqKbkpmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GIX!A3181BF05308
FireEyeGeneric.mg.a3181bf05308cb6b
EmsisoftGen:Variant.Fugrafa.64902 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.ZPACK.Gen2
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Fugrafa.64902
McAfeeRansomware-GIX!A3181BF05308
MAXmalware (ai score=99)
PandaTrj/GdSda.A
RisingRansom.Zerber!8.518C (CLOUD)
YandexTrojan.Zerber!cqEtY6F1JC8
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxMBEpsA

How to remove Fugrafa.64902?

Fugrafa.64902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment