Categories: Malware

Fugrafa.3794 removal instruction

The Fugrafa.3794 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.3794 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Fugrafa.3794?


File Info:

name: 759B057448C7BE477794.mlwpath: /opt/CAPEv2/storage/binaries/851cbb4cb51f5e023b948fa929c9ba16af437d88e9f89d594860ab07186f8f9bcrc32: A7416D7Emd5: 759b057448c7be47779468e47423936dsha1: 15d548a03d578f9db91cf8e53e81101bee257384sha256: 851cbb4cb51f5e023b948fa929c9ba16af437d88e9f89d594860ab07186f8f9bsha512: 19d32928215a420d658e6f248d6d623b53bbe71e2e1d69c777d94bf6ec455783899bd3b82aa44612a1a82a8b4eb0041e2093171ca062b020e7568e8213095605ssdeep: 3072:ATb0gTbnGZ7/d5bpnsDbphOg8JaTK8zZa4f1mTLr2LkNq1x:rSGZ7HIX8JaTKsZa4f7type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T13814D7957355D4A7D5B718B9DC29A9F830A7BC59C4A8F20F2C923E0A71F2343107AE1Bsha3_384: 2a99cea5cf2190499c2e1238a62ac57f44f80e9c95d3297ae02e554250e2fd994830687f7209d3f679d089f788b70395ep_bytes: 6003f833cb412bfe4f23f903d80bfb6atimestamp: 2018-05-09 13:54:24

Version Info:

0: [No Data]

Fugrafa.3794 also known as:

Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.FFRat.m!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Fugrafa.3794
FireEye Generic.mg.759b057448c7be47
McAfee Trojan-FPPZ!759B057448C7
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 004fd41d1 )
Alibaba Backdoor:Win32/FFRat.5eb5fb37
K7GW Trojan ( 004fd41d1 )
Cybereason malicious.448c7b
VirIT Trojan.Win32.Spy.BEYM
Elastic malicious (high confidence)
ESET-NOD32 Win32/Agent.SVO
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Backdoor.Win32.FFRat.gen
BitDefender Gen:Variant.Fugrafa.3794
NANO-Antivirus Trojan.Win32.Dimnie.fbswyq
Avast Win32:Malware-gen
Tencent Win32.Backdoor.Ffrat.Ahyp
Ad-Aware Gen:Variant.Fugrafa.3794
Emsisoft Gen:Variant.Fugrafa.3794 (B)
Comodo Malware@#n0gs25d4602o
DrWeb Trojan.PWS.Spy.20916
Zillya Trojan.Agent.Win32.2640250
TrendMicro TSPY_FAREIT.UHBADDH
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.ch
Trapmine malicious.high.ml.score
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Krypt
GData Gen:Variant.Fugrafa.3794
Jiangmin Trojan.Dimnie.dm
Avira HEUR/AGEN.1233241
MAX malware (ai score=100)
Arcabit Trojan.Fugrafa.DED2
Microsoft Trojan:Win32/CryptInject
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Kryptik.C2500162
BitDefenderTheta Gen:NN.ZexaF.34742.lqW@aSuELvaG
ALYac Gen:Variant.Fugrafa.3794
VBA32 BScope.Malware-Cryptor.MTA
Malwarebytes Malware.AI.4201969131
TrendMicro-HouseCall TSPY_FAREIT.UHBADDH
Rising Trojan.Generic@AI.100 (RDML:Qj+wVhebeJd52l0PRVV1rQ)
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.GGXB!tr
AVG Win32:Malware-gen
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (W)

How to remove Fugrafa.3794?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4222225806 malicious file

The Malware.AI.4222225806 is considered dangerous by lots of security experts. When this infection is active,…

44 mins ago

Malware.AI.1862100968 removal guide

The Malware.AI.1862100968 is considered dangerous by lots of security experts. When this infection is active,…

50 mins ago

Win32:VB-OLS [Trj] removal

The Win32:VB-OLS [Trj] is considered dangerous by lots of security experts. When this infection is…

59 mins ago

How to remove “Trojan:Win32/Smokeloader.CCDO!MTB”?

The Trojan:Win32/Smokeloader.CCDO!MTB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “TrojanDownloader:MSIL/RedLineStealer.KL!MTB”?

The TrojanDownloader:MSIL/RedLineStealer.KL!MTB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

How to remove “Malware.AI.4139232050”?

The Malware.AI.4139232050 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago