Malware

Fugrafa.628 removal guide

Malware Removal

The Fugrafa.628 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.628 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fugrafa.628?


File Info:

name: 73427C11420207604C33.mlw
path: /opt/CAPEv2/storage/binaries/61193f70cc9397c69ce22c6cead9945aa2e6d296fad949831ba5c82a41efcc97
crc32: FC8A3372
md5: 73427c11420207604c33ff3c4cc7f3cb
sha1: c0bdb5fad0089d69a7741fbd0eaeec0b21e98d14
sha256: 61193f70cc9397c69ce22c6cead9945aa2e6d296fad949831ba5c82a41efcc97
sha512: 05016f70f5bd39c078dbae8f0b7a8815bc217698d94e9498158e8f30cf5513158f2940673d14cc2809758d3bada7eaa2ae88a739f88be5d89d3c58ffaf0bc80d
ssdeep: 6144:D4m8xK9rreuJ3BmaMF2YTV/8RpIJaMtIECBHMC9Wb:Dp8xK9rrZjm92YTh8vc+Wb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7546C1277E0C832F2B24B3459798A958A3ABD31AF75C5CB76802F1D1D31AD4DA39363
sha3_384: 5e47bdd25431ac909cf33efe4e752802deaccbe87ca7652efda8d7ed6746562b2ce0990486c56d7391133f13e0aae086
ep_bytes: e807320000e91efeffff2da403000074
timestamp: 2018-12-02 18:07:23

Version Info:

0: [No Data]

Fugrafa.628 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ursnif.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.628
FireEyeGeneric.mg.73427c1142020760
ALYacGen:Variant.Fugrafa.628
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Ursnif.Win32.4654
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ursnif.acf62575
K7GWTrojan ( 00542cd11 )
K7AntiVirusTrojan ( 00542cd11 )
SymantecPacked.Generic.521
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.ECCA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Ursnif.afdd
BitDefenderGen:Variant.Fugrafa.628
NANO-AntivirusTrojan.Win32.Ursnif.fkvdee
AvastFileRepMalware [Trj]
TencentWin32.Trojan-Spy.Ursnif.Ngil
SophosMal/Generic-S
DrWebTrojan.PWS.Papras.3647
VIPREGen:Variant.Fugrafa.628
TrendMicroMal_Swizzor
McAfee-GW-EditionBehavesLike.Win32.Infected.dh
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Fugrafa.628 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fugrafa.628
JiangminTrojanSpy.Ursnif.bwk
WebrootW32.Trojan.Gen
Antiy-AVLTrojan[Spy]/Win32.Ursnif
XcitiumMalware@#2uizi0a8e7cog
ArcabitTrojan.Fugrafa.628
ZoneAlarmTrojan-Spy.Win32.Ursnif.afdd
MicrosoftTrojanSpy:Win32/Ursnif
GoogleDetected
McAfeeArtemis!73427C114202
MAXmalware (ai score=100)
VBA32BScope.Trojan.Cloxer
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Swizzor
RisingTrojan.Generic@AI.100 (RDML:MzaXVsQmgQGhyFGW+KfTrA)
IkarusTrojan.AD.UrsnifDropper
FortinetW32/GenKryptik.CSWH!tr
BitDefenderThetaGen:NN.ZexaF.36318.rqZ@a8jnTye
AVGFileRepMalware [Trj]
Cybereasonmalicious.142020
DeepInstinctMALICIOUS

How to remove Fugrafa.628?

Fugrafa.628 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment