Malware

Fugrafa.28844 removal instruction

Malware Removal

The Fugrafa.28844 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.28844 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Fugrafa.28844?


File Info:

name: CBAFB6341427FC4076CC.mlw
path: /opt/CAPEv2/storage/binaries/6aa1b82fe8e414e0f77132b37f39607590acfd12ec7f760383a9b13d8a29ecff
crc32: B507BC19
md5: cbafb6341427fc4076cc85c2730a9f8f
sha1: 4f7c83afff547f1f5a194a79be264b34f3a3e97f
sha256: 6aa1b82fe8e414e0f77132b37f39607590acfd12ec7f760383a9b13d8a29ecff
sha512: 9f6f8e81bc30b9f6323038cbef9632770f8cfed7906e28f10f6c54a2e683aa507b70d4af14b97e0371fe27efc14a4ef8b290ba439905ae39f6d09ebf2d353d77
ssdeep: 12288:0W+B+McMKXc3ajG+hjQKymY8efKCpD7Gj9G6G1qT8nQkCu83L3Wl/np9DBDt3kbE:0W+BxcdsqjnhMgeiCl7G0nehbGZpbD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166551227B5D084B5E4B24C3045E2E9689C2B7D324A240CA737D52ABEAF754D0CE39E77
sha3_384: 317f778114b2826cac088d12a17e4248c05f1eaef74338fe75a5c02f51c6ba2dc0a988846aacbcd6d311a745005bbc74
ep_bytes: e84c3b0a00e97afeffff3b0d08204100
timestamp: 2020-03-02 23:24:24

Version Info:

CompanyName: Google LLC
FileDescription: Google Update
FileVersion: 1.3.35.451
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: goopdate.dll
ProductName: Google Update
ProductVersion: 1.3.35.451
Translation: 0x0409 0x04b0

Fugrafa.28844 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Waldek.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.28844
FireEyeGeneric.mg.cbafb6341427fc40
McAfeeArtemis!CBAFB6341427
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0058c5711 )
K7AntiVirusTrojan ( 0058c5711 )
BitDefenderThetaGen:NN.ZexaF.34114.qv0@auS@i6ci
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Expiro.NDO
TrendMicro-HouseCallTROJ_GEN.R002C0WA222
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Fugrafa.28844
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentWin32.Virus.Expiro.Tbit
Ad-AwareGen:Variant.Fugrafa.28844
SophosGeneric ML PUA (PUA)
TrendMicroTROJ_GEN.R002C0WA222
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tt
EmsisoftGen:Variant.Fugrafa.28844 (B)
IkarusTrojan.Patched
GDataGen:Variant.Fugrafa.28844
JiangminTrojan.Generic.henif
MAXmalware (ai score=86)
ArcabitTrojan.Fugrafa.D70AC
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacGen:Variant.Fugrafa.28844
APEXMalicious
RisingVirus.Expiro!8.375 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/FileInfector.C!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.41427f

How to remove Fugrafa.28844?

Fugrafa.28844 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment