Categories: Malware

Fugrafa.64536 removal

The Fugrafa.64536 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.64536 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Fugrafa.64536?


File Info:

name: EC441F2233C3E6E7D4A2.mlwpath: /opt/CAPEv2/storage/binaries/4cd2fbc2cb54a13236ea36027d0f8e3721ab15e6c0ef9bb80427732f35ff0539crc32: BDFFDBDBmd5: ec441f2233c3e6e7d4a2f87aff9325a2sha1: 0bacd17dad9e16cd1b36f5e04a136297734b4645sha256: 4cd2fbc2cb54a13236ea36027d0f8e3721ab15e6c0ef9bb80427732f35ff0539sha512: bb14a3a729cb80acea2eec2b85c1c0d80b2f53b5bab3e20e39c478fe718d5d9ce93f32121739b306fc8c0d2ed73e1d251fa6f8a5dd894448f9842669fca0f6f4ssdeep: 1536:cpeSewu82rcrVtrWbzDbEgf1NQdEa3dqBfIe5EyzIcAqyG3/kvQxDvW8d6eGJveF:meH+UbEU1NwEa3d34fS84eXBVvDRCTtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T14EC3E14B2536F1C6FD296A3E7E68A022F3E2C8C42D14E515F60E366ECE7DE11A840765sha3_384: 77d2d2f94147db99c64f00372361edef7dab2009c909fa66718a6eaf7bf5d6bd9d78433d85d6e89a637ae4ee7c2c0855ep_bytes: 558bec83c4f0871d125040008d7c24f8timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Fugrafa.64536 also known as:

Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Agentb.lI4v
MicroWorld-eScan Gen:Variant.Fugrafa.64536
ClamAV Win.Downloader.112725-1
FireEye Generic.mg.ec441f2233c3e6e7
CAT-QuickHeal Trojan.Renos.PG
ALYac Gen:Variant.Fugrafa.64536
Malwarebytes Malware.Heuristic.1003
VIPRE Gen:Variant.Fugrafa.64536
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW Trojan ( 004bcce41 )
K7AntiVirus Trojan ( 004bcce41 )
BitDefenderTheta Gen:NN.ZexaF.34682.hmW@aanpy4hc
VirIT Trojan.Win32.Generic.INS
Cyren W32/FakeAlert.AEB.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 Win32/TrojanDownloader.FakeAlert.BBT
TrendMicro-HouseCall TROJ_KRYPTK.SMCA
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan-Downloader.Win32.CodecPack.annb
BitDefender Gen:Variant.Fugrafa.64536
NANO-Antivirus Trojan.Win32.Dwn.ipcvc
Avast Win32:Downloader-GGV [Trj]
Tencent Malware.Win32.Gencirc.10ce4717
Ad-Aware Gen:Variant.Fugrafa.64536
Emsisoft Gen:Variant.Fugrafa.64536 (B)
Comodo Packed.Win32.MUPX.Gen@24tbus
DrWeb Trojan.Fakealert.56214
Zillya Trojan.FakeAV.Win32.93707
TrendMicro TROJ_KRYPTK.SMCA
McAfee-GW-Edition BehavesLike.Win32.Dropper.ct
Trapmine malicious.moderate.ml.score
Sophos ML/PE-A + Mal/FakeAV-NJ
Ikarus Trojan-Downloader.Win32.Voila
Jiangmin TrojanDownloader.CodecPack.coh
Webroot W32.Malware.Gen
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=87)
Antiy-AVL Trojan/Generic.ASMalwS.14
Microsoft TrojanDownloader:Win32/Renos.PG
GData Gen:Variant.Fugrafa.64536
Google Detected
AhnLab-V3 Downloader/Win32.CodecPack.C64755
McAfee Downloader-CEW.ak
VBA32 TScope.Malware-Cryptor.SB
APEX Malicious
Rising Trojan.Occamy!8.F1CD (TFE:2:WgE2vnHb6pV)
Yandex Trojan.DL.CodecPack!pKStA7RP1dI
SentinelOne Static AI – Malicious PE
Fortinet W32/CodecPack.ANNB!tr.dldr
AVG Win32:Downloader-GGV [Trj]
Cybereason malicious.233c3e
Panda Trj/Renos.gen

How to remove Fugrafa.64536?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4222225806 malicious file

The Malware.AI.4222225806 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.1862100968 removal guide

The Malware.AI.1862100968 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Win32:VB-OLS [Trj] removal

The Win32:VB-OLS [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago

How to remove “Trojan:Win32/Smokeloader.CCDO!MTB”?

The Trojan:Win32/Smokeloader.CCDO!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “TrojanDownloader:MSIL/RedLineStealer.KL!MTB”?

The TrojanDownloader:MSIL/RedLineStealer.KL!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

How to remove “Malware.AI.4139232050”?

The Malware.AI.4139232050 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago