Malware

Fugrafa.8101 removal instruction

Malware Removal

The Fugrafa.8101 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.8101 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

wx.go890.com
cnwx.58ad.cn
www.58sky.com
wdx.go890.com
www.ip138.com
ip.catr.cn

How to determine Fugrafa.8101?


File Info:

crc32: 4838A5B5
md5: f372e3560228f8b265a01e806f2496e2
name: F372E3560228F8B265A01E806F2496E2.mlw
sha1: ee344c15e095f1fa33f7469d07376d9e6cc31897
sha256: bb104b8631bf9268f689b9a1bd3d293048cdb2f06d01eaae87962107b0b48391
sha512: 499767eee0ed06258d471399d8fc016afe2b21c634d8a6061d08b9ec3ca70cf691084d9609fc17a3033018df3022781bd8aeba9710b412f44a4ed2b03d80adfa
ssdeep: 6144:gJ82asJfnlAJwT71w+DtmVlTWw8oY4JHfTcE6sTNrCMHJeTBh+:gOWJ8wT7SoScCY4JHLcElTNm8eT
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Fugrafa.8101 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.8101
FireEyeGeneric.mg.f372e3560228f8b2
McAfeeGenericRXNA-ZW!F372E3560228
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Fugrafa.8101
K7GWTrojan ( 004f34121 )
K7AntiVirusTrojan ( 004f34121 )
BitDefenderThetaAI:Packer.89A779D019
CyrenW32/Trojan.FVC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Delf-6832441-0
KasperskyTrojan.Win32.Reconyc.ihln
NANO-AntivirusTrojan.Win32.Reconyc.icdzbt
RisingTrojan.AgentTesla!8.104D5 (TFE:3:kEVWd7r4luP)
Ad-AwareGen:Variant.Fugrafa.8101
EmsisoftGen:Variant.Fugrafa.8101 (B)
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoader23.30684
ZillyaTrojan.Reconyc.Win32.30687
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
SophosML/PE-A + Troj/Agent-AJFK
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Reconyc.hfc
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Win32.Asacky
MicrosoftTrojan:Win32/Wacatac.DB!ml
ArcabitTrojan.Fugrafa.D1FA5
ZoneAlarmTrojan.Win32.Reconyc.ihln
GDataGen:Variant.Fugrafa.8101
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Reconyc.C4266211
Acronissuspicious
VBA32BScope.Trojan.Reconyc
MAXmalware (ai score=88)
MalwarebytesTrojan.Reconyc
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Delf.TJJ
TencentMalware.Win32.Gencirc.10ce2898
YandexTrojan.Reconyc!COD8FvyT8sg
IkarusTrojan-Downloader.Win32.QQHelper
eGambitUnsafe.AI_Score_97%
FortinetW32/Fugrafa.8101!tr
AVGWin32:Evo-gen [Susp]
Qihoo-360HEUR/QVM19.1.061F.Malware.Gen

How to remove Fugrafa.8101?

Fugrafa.8101 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment