Malware

Fugrafa.258729 (B) removal guide

Malware Removal

The Fugrafa.258729 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.258729 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.258729 (B)?


File Info:

name: 16094AA7A6C24C8967D3.mlw
path: /opt/CAPEv2/storage/binaries/94d90fed209b9136953a6a51be389f2277e88003824c86a764f8a44da22cfbb5
crc32: 40FFD49A
md5: 16094aa7a6c24c8967d39325cc23e691
sha1: 074177d02da5b7c90dad3752131b3e2e62f44f43
sha256: 94d90fed209b9136953a6a51be389f2277e88003824c86a764f8a44da22cfbb5
sha512: 6d5c87ec54191251f3d6cb9da0981b0ecc47d523b44ba8f1da9e1ecaa873c94d9fba16550f3c7ac1c27925dd54f022ecfab0cad6ce18dcfadf2c4904289223b0
ssdeep: 384:7WJdpfL/Ux9d309RXjXz7XjCWwqK8Wzz8WW5bIwHHKuNIhxaZUMblYlM:SvpfQbG9xjXvKBBW5bHKuuhxaV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CCC27DC7F6818872EAE559B519B10EB9C2FFB1206A67A9538F30D1160EF10BCE61C35D
sha3_384: 795514781abfa938b9ff4524c51461e3a25c48d26633760f4dae9182973132ff0050bcab148d0ac516acf92f76273a5d
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.258729 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Fugrafa.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop20.10627
MicroWorld-eScanGen:Variant.Fugrafa.258729
FireEyeGeneric.mg.16094aa7a6c24c89
McAfeeGenericRXNV-VM!16094AA7A6C2
MalwarebytesMalware.AI.2397151589
SangforTrojan.Win32.Agent.Vb2q
K7AntiVirusPassword-Stealer ( 005937271 )
BitDefenderGen:Variant.Fugrafa.258729
K7GWPassword-Stealer ( 005937271 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OOO
TrendMicro-HouseCallTROJ_GEN.R002C0PG122
Paloaltogeneric.ml
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
AlibabaTrojanPSW:Win32/SelfDel.8d12fe24
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
ViRobotTrojan.Win32.Z.Selfdel.26112.DTK
AvastWin32:Malware-gen
RisingStealer.Agent!1.DE3E (CLASSIC)
Ad-AwareGen:Variant.Fugrafa.258729
TACHYONTrojan/W32.Fugrafa.26112
EmsisoftGen:Variant.Fugrafa.258729 (B)
VIPREGen:Variant.Fugrafa.258729
TrendMicroTROJ_GEN.R002C0PG122
McAfee-GW-EditionGenericRXNV-VM!16094AA7A6C2
SophosMal/Generic-S + Troj/PWS-CMJ
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fugrafa.258729
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Fugrafa.258729
MAXmalware (ai score=85)
CylanceUnsafe
APEXMalicious
TencentTrojan.Win32.Selfdel.xb
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.7a6c24
PandaTrj/Genetic.gen

How to remove Fugrafa.258729 (B)?

Fugrafa.258729 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment