Malware

Fugrafa.258729 removal

Malware Removal

The Fugrafa.258729 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.258729 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.258729?


File Info:

name: 37A6CF1589B008C0EE4F.mlw
path: /opt/CAPEv2/storage/binaries/09557d6e500453e273248dfac62cf4f4db5f8541d04024f887e0ff0b65238f48
crc32: AAC7F81D
md5: 37a6cf1589b008c0ee4fd15dffc0bd2a
sha1: f82d213f310fc47bacf3318ba1f6f75eb9c5c5ae
sha256: 09557d6e500453e273248dfac62cf4f4db5f8541d04024f887e0ff0b65238f48
sha512: 5292e3d3d46c88fc3735ff6eb726b649c1ff4d901bdc30c5d52a97fddd773c49d8a04445f8dfc4cde06d0a665520296e0187447a67dd9e91500ae9adeb3bc288
ssdeep: 384:yWwAOqs1Ux9p09RXjXz7XjCWwqK8Wzz8WW5bIwHt+bk5yA0rrmAdLaDWqOn1GPZL:hwArb29xjXvKBBW5bMVA0rIieZL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B2C2AE47B7948F33E9C006329C7E29BD82FE38B0666955924B70EF861DE7250E6191CE
sha3_384: b6047d398554b93dc056c11c3fbbeeeaf0549dae62c2884ba1641f2bc690d73b9a9eaadc9260a095f7ad05daebcc9968
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.258729 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.258729
FireEyeGeneric.mg.37a6cf1589b008c0
McAfeeGenericRXNV-VM!37A6CF1589B0
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
CyrenW32/Agent.ENB.gen!Eldorado
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fugrafa.258729
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fugrafa.258729
DrWebTrojan.MulDrop20.10627
McAfee-GW-EditionGenericRXNV-VM!37A6CF1589B0
EmsisoftGen:Variant.Fugrafa.258729 (B)
GDataGen:Variant.Fugrafa.258729
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MAXmalware (ai score=89)
ZoneAlarmHEUR:Trojan.Win32.SelfDel.vho
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
ALYacGen:Variant.Fugrafa.258729
TACHYONTrojan/W32.Fugrafa.26112
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.589b00
PandaTrj/Genetic.gen

How to remove Fugrafa.258729?

Fugrafa.258729 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment