Malware

About “Fugrafa.97190” infection

Malware Removal

The Fugrafa.97190 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.97190 virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates Zeus (Banking Trojan) mutexes
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Fugrafa.97190?


File Info:

crc32: 9881C74A
md5: 0e5ffeee6782cf186a3be3ca89bbdcc1
name: 0E5FFEEE6782CF186A3BE3CA89BBDCC1.mlw
sha1: 634d76c807eb52a39be76ac06419697a16d3cf4f
sha256: 3c2610650607a84cc055787e6ee6c6da6d332fa806559ca70850dfaf5165df34
sha512: 69e472257168ba0c483a985245e4f4ff15751abe40c01a43bc81e0dd44670188e42833efa3b4fef0d2d8b394c9f4046f636730bba623202cfd18ad47c54a9db6
ssdeep: 1536:MM2NHWd10HbQpVqzOpg/LrdCTcKL3IV0awX8C+s:MrNHWdq7w2MAivawMfs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Fugrafa.97190 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop15.60538
MicroWorld-eScanGen:Variant.Fugrafa.97190
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360HEUR/QVM20.1.455B.Malware.Gen
McAfeeGenericRXMP-LB!0E5FFEEE6782
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Fugrafa.97190
Cybereasonmalicious.e6782c
TrendMicroTSPY_ZBOT.SMRL
BitDefenderThetaAI:Packer.5B8914861E
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTSPY_ZBOT.SMRL
AvastSf:Zbot-CQ [Trj]
ClamAVWin.Trojan.Zbot-9789488-0
KasperskyTrojan-Spy.Win32.Zbot.adwr
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingMalware.Zbot!8.E95E (TFE:1:T0ftm5gnxaN)
Ad-AwareGen:Variant.Fugrafa.97190
EmsisoftGen:Variant.Fugrafa.97190 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREBehavesLike.Win32.Malware.bsm (vs)
InvinceaML/PE-A
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.0e5ffeee6782cf18
JiangminTrojanSpy.Zbot.xcj
AviraTR/Crypt.XPACK.Gen
MicrosoftPWS:Win32/Zbot.gen!R
ArcabitTrojan.Fugrafa.D17BA6
ZoneAlarmTrojan-Spy.Win32.Zbot.adwr
GDataGen:Variant.Fugrafa.97190
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.R8249
VBA32SScope.Trojan.Bofa
ALYacGen:Variant.Fugrafa.97190
MAXmalware (ai score=82)
APEXMalicious
ESET-NOD32a variant of Win32/Spy.Zbot.JF
YandexTrojan.GenAsa!lCOjkCt5Rig
eGambitUnsafe.AI_Score_90%
FortinetW32/Zbot.JF!tr
AVGSf:Zbot-CQ [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Fugrafa.97190?

Fugrafa.97190 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment