Malware

How to remove “Fugrafa.26950”?

Malware Removal

The Fugrafa.26950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.26950 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics

How to determine Fugrafa.26950?


File Info:

name: 924E8B20676B6FB68957.mlw
path: /opt/CAPEv2/storage/binaries/2a41d95d9f7334f798d665d6e9e9a2489b284c875bf52367c2268a95bd27883a
crc32: 1478B6E5
md5: 924e8b20676b6fb6895723c5162c6b63
sha1: 95e74de5022de3afd990ae0a784b3428464792f0
sha256: 2a41d95d9f7334f798d665d6e9e9a2489b284c875bf52367c2268a95bd27883a
sha512: 121382e7d5a7fd839581a607aa955e945aecd620c03144c242eda6ef0836c011a686f4df382643c499b90dcbed6714026f1ccc4049c858d6e6b569dfff9626e5
ssdeep: 6144:NL9nhFzR/O1BWL9nhFzR/O1BWL9nhFzR/O1BWL9nhFzR/O1B0:lphD21BkphD21BkphD21BkphD21B0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8A4CE3A3E87B670F71895748AB83D3F8561F9335DD9A08CD7B86A023130DA47B9560E
sha3_384: 7de8830b663fcd096eeac14c5dc87ff16b9d444df53f3fa86cb0bd1f86624e6b0e730ba7e2ba7e10bd8d655002e86a77
ep_bytes: 64a1000000005589e56aff681c804000
timestamp: 2004-03-24 08:43:55

Version Info:

0: [No Data]

Fugrafa.26950 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.26950
FireEyeGeneric.mg.924e8b20676b6fb6
ALYacGen:Variant.Fugrafa.26950
CylanceUnsafe
ZillyaTrojan.CmjSpy.Win32.51
SangforTrojan.Win32.Save.a
Cybereasonmalicious.0676b6
SymantecBackdoor.MLink
ESET-NOD32a variant of Win32/CmjSpy
APEXMalicious
KasperskyHEUR:Trojan.Win32.SchoolBoy.gen
BitDefenderGen:Variant.Fugrafa.26950
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Fugrafa.26950
SophosML/PE-A
F-SecureTrojan.TR/Hijacker.Gen
DrWebBackDoor.CmjSpy.origin
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftGen:Variant.Fugrafa.26950 (B)
IkarusBackdoor.Win32.Cmjspy
JiangminBackdoor/MagicLink.av.Dropper
AviraTR/Hijacker.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan[Backdoor]/Win32.Cmjspy
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fugrafa.26950
CynetMalicious (score: 100)
McAfeeBackDoor-WB.gen.c
VBA32BScope.Trojan.Genome
MalwarebytesMalware.AI.260027489
RisingTrojan.Generic@ML.94 (RDML:tA8jENLXcyGwFxGWOTlMvQ)
YandexTrojan.GenAsa!v2VH4KC9g8g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Cmjspy.AW!tr
BitDefenderThetaAI:Packer.84D661C41F
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fugrafa.26950?

Fugrafa.26950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment