Adware

About “Adware.Fragtor.364” infection

Malware Removal

The Adware.Fragtor.364 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Fragtor.364 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Fragtor.364?


File Info:

name: 99676050652819A0A116.mlw
path: /opt/CAPEv2/storage/binaries/97496e0250f6455b06da5d718d9ae82b7c299f8a6bedb3e730b1abe2e009fe97
crc32: C6903BF4
md5: 99676050652819a0a1167f08f4b23df1
sha1: f0cb03e9a9d551d7ccbd7f7f5ad7ef35858d7afa
sha256: 97496e0250f6455b06da5d718d9ae82b7c299f8a6bedb3e730b1abe2e009fe97
sha512: 276034874894b2438f28ac19303ab7d5ab2cfd7b6d6539337b2b9f96b428215354a5c32dc8c59925e1cc320c6406699fd1cf8665ceda082d0d89b6089208b4d6
ssdeep: 98304:nJ5f6gIJl2WWGQKtpcqalW31mH/C3nZVx7FISFLOAkGkzdnEVomFHKnPn4/Dx:GgIceeS0C3nZVxJISFLOyomFHKnPeDx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF56BF317E4D8836E46301334AAAB77D956FBE38232445D343947A7A6F322C2193B677
sha3_384: 0f00def80bd5b5b0fd83d1f25a3afb3a75774a554ef0ca5da6008b104fbc0a6b88915cc2cf1e89a549cce093f01e1a9e
ep_bytes: e877080000e97afeffff8b4df464890d
timestamp: 2023-06-20 02:01:54

Version Info:

CompanyName: Xiamen Source Spacetime Technology Co., Ltd.
FileDescription: 青猴浏览器安装程序
FileVersion: 23.2.0.12
InternalName: QingHouSetup.exe
LegalCopyright: Copyright 2023 Source Spacetime Ltd. All Rights Reserved.
OriginalFilename: QingHouSetup.exe
ProductName: 青猴浏览器
ProductVersion: 23.2.0.12
Translation: 0x0804 0x04b0

Adware.Fragtor.364 also known as:

BkavW32.Common.80C813E5
MicroWorld-eScanGen:Variant.Adware.Fragtor.364
FireEyeGen:Variant.Adware.Fragtor.364
Cylanceunsafe
K7AntiVirusAdware ( 005a56921 )
AlibabaAdWare:Win32/Tongbuxing_AGen.0b445bf1
K7GWAdware ( 005a56921 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Adware.Tongbuxing_AGen.A
BitDefenderGen:Variant.Adware.Fragtor.364
AvastWin32:AdwareX-gen [Adw]
EmsisoftGen:Variant.Adware.Fragtor.364 (B)
F-SecureAdware.ADWARE/Redcap.nyodf
VIPREGen:Variant.Adware.Fragtor.364
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Tongbuxing
GDataGen:Variant.Adware.Fragtor.364
AviraADWARE/Redcap.nyodf
ArcabitTrojan.Adware.Fragtor.364
ALYacGen:Variant.Adware.Fragtor.364
MAXmalware (ai score=68)
MalwarebytesGeneric.Malware/Suspicious
RisingAdware.Tongbuxing!8.13D06 (CLOUD)
MaxSecureTrojan.Malware.218663034.susgen
FortinetRiskware/Tongbuxing_AGen
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Adware.Fragtor.364?

Adware.Fragtor.364 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment