Malware

Fugrafa.5885 (B) removal tips

Malware Removal

The Fugrafa.5885 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.5885 (B) virus can do?

  • Creates RWX memory
  • Loads a driver
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Fugrafa.5885 (B)?


File Info:

crc32: 598272DE
md5: 90d0d665cd5a7091d7aa0edc8287658a
name: 90D0D665CD5A7091D7AA0EDC8287658A.mlw
sha1: 160990386ba1eb68bb9a8fae1a8f9c7a202c97dd
sha256: 90fe4c3ac3833280acebd78cab2f65c4fa98a88b516d2405211aa98f1f127e40
sha512: 2a93f871162b665587cc90dbe7e16d50354caab67608a9277c2fdfb8b6e99cc663c8e387ccd68bfe786a627746c685828e5c4f392c0645984f6ea5ca0df8552a
ssdeep: 98304:aI9BsiU+d8Xxd8Xv8XWU78Xv8XWUb9BsiU+d8Xxd8Xv8Xy:aI9hUzsEGUgEGUb9hUzsEC
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Fugrafa.5885 (B) also known as:

K7AntiVirusTrojan ( 0008550a1 )
Elasticmalicious (high confidence)
DrWebTool.HideProc.27
ClamAVWin.Trojan.Hideproc-77
ALYacGen:Variant.Fugrafa.5885
CylanceUnsafe
ZillyaTrojan.Delf.Win32.52545
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0008550a1 )
Cybereasonmalicious.5cd5a7
CyrenW32/Delf.IQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.NZQ
APEXMalicious
AvastWin32:HideProc-N [PUP]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Banload.aalpj
BitDefenderGen:Variant.Fugrafa.5885
NANO-AntivirusRiskware.Win32.HideProc.crvalg
MicroWorld-eScanGen:Variant.Fugrafa.5885
TencentMalware.Win32.Gencirc.10b87824
Ad-AwareGen:Variant.Fugrafa.5885
SophosTroj/Ghetifuh-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZelphiF.34236.@xZ@aOrrWxbb
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRTKT_HIDEPROC.BB
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.90d0d665cd5a7091
EmsisoftGen:Variant.Fugrafa.5885 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Banload.akge
AviraTR/Rootkit.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.112E4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Fugrafa.D16FD
ZoneAlarmTrojan-Downloader.Win32.Banload.aalpj
GDataGen:Variant.Fugrafa.5885
AhnLab-V3Trojan/Win.Banload.R447588
Acronissuspicious
McAfeeGenericRXAA-AA!90D0D665CD5A
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Banload
PandaTrj/Genetic.gen
TrendMicro-HouseCallRTKT_HIDEPROC.BB
RisingRootKit.Win32.HideProc.l (CLASSIC)
YandexTrojan.GenAsa!nT9bLJVyuj4
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.500016.susgen
FortinetW32/Delf.NZQ!tr
AVGWin32:HideProc-N [PUP]

How to remove Fugrafa.5885 (B)?

Fugrafa.5885 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment