Malware

What is “Fugrafa.164258”?

Malware Removal

The Fugrafa.164258 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.164258 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Anomalous binary characteristics

How to determine Fugrafa.164258?


File Info:

name: F4FA6C2A221ED08F59AB.mlw
path: /opt/CAPEv2/storage/binaries/c8e6c9b45c3cb5ecce85a464de52d0c1743cc8ccd919c2c57c89d3f5d3d89253
crc32: A7DF3A1D
md5: f4fa6c2a221ed08f59ab0cbf9c2f0b8c
sha1: 3f2f39a47869df05d3ae8477e0782e87a4c04624
sha256: c8e6c9b45c3cb5ecce85a464de52d0c1743cc8ccd919c2c57c89d3f5d3d89253
sha512: 5d70654c12efb5fdb3d2f11572844536e6f8a00ba7d077a84c90ebf4e77cb37fbbca55d4359a22be7626848e8765fe8910defb3284c386662067616741a32188
ssdeep: 12288:pKyGnp0KrvoxzyDG+/fscKyGnp0KrvoxzyDG+/fsa:pvJaAxSDHvJaAxSDh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131C47C21BA90C033F55301758979DB6AB92AB9305B3560C7E3DC4E7D9FA22D2963831F
sha3_384: bcbbcc43b702da39a58c7550646d42f415152b1d4496c538f8be5e250afae84aa1d63963e3921091eee0cc7f5218ffc6
ep_bytes: e8c6640000e995feffff3b0d54b64300
timestamp: 2021-09-08 03:49:55

Version Info:

CompanyName: 上海跃客网络科技有限公司
FileDescription: KappaCamera
FileVersion: 1.0.0.1
InternalName: Gif
LegalCopyright: Copyright (C) 2021
OriginalFilename: KappaCameraT.exe
ProductName: 联系我们http://show.vgood.top/feedback/
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Fugrafa.164258 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Fugrafa.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.164258
FireEyeGeneric.mg.f4fa6c2a221ed08f
CAT-QuickHealPUA.AgentRI.S23757129
McAfeeRDN/Generic PUP.x
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWAdware ( 00578df21 )
K7AntiVirusAdware ( 00578df21 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BK potentially unwanted
Paloaltogeneric.ml
BitDefenderGen:Variant.Fugrafa.164258
AvastWin32:Adware-gen [Adw]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Fugrafa.164258
SophosGeneric PUA DP (PUA)
TrendMicroTROJ_GEN.R03FC0PKO21
McAfee-GW-EditionRDN/Generic PUP.x
EmsisoftGen:Variant.Fugrafa.164258 (B)
GDataGen:Variant.Fugrafa.164258
Antiy-AVLTrojan/Generic.ASMalwS.34D5DCF
ArcabitTrojan.Fugrafa.D281A2
MicrosoftPUA:Win32/Softcnapp
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_Generic.R365583
BitDefenderThetaGen:NN.ZexaF.34294.Hu3@a4P!o3mj
ALYacGen:Variant.Fugrafa.164258
MAXmalware (ai score=84)
VBA32BScope.Trojan.Sdum
MalwarebytesPUP.Optional.Softcnapp
TrendMicro-HouseCallTROJ_GEN.R03FC0PKO21
RisingAdware.Agent!1.CE32 (CLASSIC)
YandexRiskware.Agent!MzBhbWNDlpY
SentinelOneStatic AI – Malicious PE
FortinetAdware/Softcnapp.BK
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.a221ed

How to remove Fugrafa.164258?

Fugrafa.164258 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment