Malware

How to remove “Fugrafa.4488”?

Malware Removal

The Fugrafa.4488 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.4488 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Nymaim malware
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

atjcnibbt.pw
phcvitle.net
iydimen.pw
eukbdszutgj.pw
wxisteqoi.pw
fdxwzfea.pw
ulgrboeel.net
nbexr.net
vcqioggbd.com
ufhttwrlflzo.com
iuxrmi.net
nnhwvlmfvysz.net
ixwbbpwebfy.pw
jjaztnpco.pw
eluigvzws.net
xvwfcjorolvq.pw
uvhdcul.net
awvows.pw
dibcgzmnuncj.net
rfbvrhddm.pw
obyllecwkh.pw
byhvpugdj.net
wpkjncn.com
xowbo.com
vwmttyn.com
hcttdfcncurj.pw
qiklymyhigot.com
glpzlpxi.in
ixbepzqifuco.in
quiibois.pw
zoasbv.pw
yjihndwlmu.in
uwwxaqncbz.net
repsnlospp.in
nrfujnswy.com
stjgdrrxlg.net
viumkqenz.in
rvxihxwql.pw
ywhgz.pw
fphxcynz.in

How to determine Fugrafa.4488?


File Info:

crc32: 4D81D9B7
md5: 7720efae697fef97a697932fcc94e031
name: 7720EFAE697FEF97A697932FCC94E031.mlw
sha1: a7915944b065bc4864d713d498ea8cac56e8c5ee
sha256: 60233dce9422240df348a9d863b02900845ab520f74089beb082c20c756352c8
sha512: 75975731cf04397f3fd337cfbc267aa04ece4664d125428a9671d7dc81c48919262fbeac1c63f58e39c52ce3320710f54f30c087fd0de34abc5e15f8dabcc259
ssdeep: 24576:iFXX643y5cUCFIqrQ6bAgzObqc64u5KRJvcpnD:iX9UiIutAg8Y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Fugrafa.4488 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052ef101 )
Elasticmalicious (high confidence)
DrWebTrojan.Nymaim.221
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.4488
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.e8bf80be
K7GWTrojan ( 0052ef101 )
Cybereasonmalicious.e697fe
CyrenW32/Nymaim.CJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GEKI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fugrafa.4488
NANO-AntivirusTrojan.Win32.Kryptik.fdfrxl
MicroWorld-eScanGen:Variant.Fugrafa.4488
TencentMalware.Win32.Gencirc.10c8faed
Ad-AwareGen:Variant.Fugrafa.4488
SophosMal/Generic-S
ComodoMalware@#ve7b1dk5exno
BitDefenderThetaGen:NN.ZexaF.34236.0uW@aqt0W2l
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJV21
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.7720efae697fef97
EmsisoftGen:Variant.Fugrafa.4488 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Regsup.als
AviraHEUR/AGEN.1106517
Antiy-AVLTrojan/Generic.ASMalwS.264EB1D
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Fugrafa.4488
TACHYONTrojan/W32.Agent.864768.BN
AhnLab-V3Malware/Win32.Generic.C2558060
Acronissuspicious
McAfeeGenericRXFQ-IE!7720EFAE697F
MAXmalware (ai score=94)
VBA32BScope.Trojan.Regsup
MalwarebytesTrojan.Nymaim.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJV21
RisingTrojan.Generic@ML.85 (RDML:2xijejobMK+SRMX0Ah3dww)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GHFA!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Fugrafa.4488?

Fugrafa.4488 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment