Malware

Fragtor.22427 (B) removal instruction

Malware Removal

The Fragtor.22427 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.22427 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.22427 (B)?


File Info:

name: 532C37EB81D66966803E.mlw
path: /opt/CAPEv2/storage/binaries/765670cf1e0a8fb1ede48ad80a365086a029e17e65dae1bb76652a2e3d6e811c
crc32: A75ADEDD
md5: 532c37eb81d66966803e0f034537e8ce
sha1: 31831d88fc7b1683e755482c9a55032f01d8e722
sha256: 765670cf1e0a8fb1ede48ad80a365086a029e17e65dae1bb76652a2e3d6e811c
sha512: ad735da049b1a96d55720464c9bd1a51646ad07295f3215a89760382929cbfc36ebda7b83d7a4531da44bece8725476610cc52f4ce5f9fbff5847bab96afb687
ssdeep: 49152:l1tqnVEOQn0EnqV4VYUCAliYVywEruMB1Um+MNOVIhHcbxpxBJAte7hCaFcN:67QnE0iYOC41UmfRqVpnJie7hCyw
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1ACB533600131EB85F7FD88305C232E78A7221FA74A96FB7872E16D824325759161EFF9
sha3_384: 21e10fc277f7338977c6eb2c0b063cb321babed410c6f4f3199ac31faba976ae8418122c4e29ee892a5e698665b24d0e
ep_bytes: b8000000005621df21db435a4f5221ff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.22427 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Fragtor.22427
FireEyeGeneric.mg.532c37eb81d66966
McAfeeGenericRXAA-FA!532C37EB81D6
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.b81d66
BitDefenderThetaGen:NN.ZexaF.34062.XmW@aW59qJb
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.22427
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.22427
EmsisoftGen:Variant.Fragtor.22427 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Injector
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.C688
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ArcabitTrojan.Fragtor.D579B
GDataGen:Variant.Fragtor.22427
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R436973
VBA32Trojan.Packed
ALYacGen:Variant.Fragtor.22427
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Kryptik!1.D238 (CLASSIC)
YandexTrojan.Copak!qadGnM+PZI4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.22427 (B)?

Fragtor.22427 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment