Malware

About “Fragtor.4762” infection

Malware Removal

The Fragtor.4762 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.4762 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Fragtor.4762?


File Info:

name: 5156319E182E6131F87A.mlw
path: /opt/CAPEv2/storage/binaries/a8fd004da8e47bca7cf9aee30619b5629b386527726b2eba3fb018f32254bbb1
crc32: C55FECA5
md5: 5156319e182e6131f87a9bc88178ef93
sha1: 1afeef9cfe341eb17ba878619c22c5f2d39cb283
sha256: a8fd004da8e47bca7cf9aee30619b5629b386527726b2eba3fb018f32254bbb1
sha512: 95e3df5c664abf3e1f9649e05c51145c73d9ae4ccb761e68bf5ad64b6e4f1b721f08be197b641e812576887f2e42225815f69e8fdba87f26f7e8b01c7d66849c
ssdeep: 1536:d10aCe0RWpaOp8lJR/Q2PutRsD/Q5LTvEe79l:gPe0gpaOp8lJR/QmuDKS5l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5B34C23DDE80FD8DB9511B11424236C866B2C6081A19F0B964E7EFEA9B1DC37DA474B
sha3_384: d546d3bbdf93390dc696b1b5c4d80876b3b26cb95636b4bfa91c7ef31b341af1834cbcc31c9edcf3466f52d86a95c04a
ep_bytes: 68a4194000e8eeffffff000000000000
timestamp: 2009-12-04 13:35:59

Version Info:

Translation: 0x0804 0x04b0
CompanyName: xyjj
ProductName: TEXTPRT
FileVersion: 1.00
ProductVersion: 1.00
InternalName: printbmp
OriginalFilename: printbmp.exe

Fragtor.4762 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
AVGWin32:Virtu-F [Inf]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.4762
FireEyeGeneric.mg.5156319e182e6131
SkyhighBehavesLike.Win32.Generic.ct
McAfeeArtemis!5156319E182E
MalwarebytesGeneric.Malware.AI.DDS
AlibabaTrojan:Win32/Virut.019204d8
Cybereasonmalicious.e182e6
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Fragtor.4762
AvastWin32:Virtu-F [Inf]
EmsisoftGen:Variant.Fragtor.4762 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Fragtor.4762
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/Virut.AM.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Antiy-AVLVirus/Win64.Expiro.rsrc
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Fragtor.D129A
GDataGen:Variant.Fragtor.4762
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Fragtor.4762
Cylanceunsafe
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
BitDefenderThetaGen:NN.ZevbaF.36802.hq1@a8DY48cb
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Fragtor.4762?

Fragtor.4762 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment