Malware

Fragtor.29455 (B) removal tips

Malware Removal

The Fragtor.29455 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.29455 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.29455 (B)?


File Info:

name: 0A72ED7F43B19D4E33C8.mlw
path: /opt/CAPEv2/storage/binaries/97dc9ff9fbd1c7dc9b9ba46491fc021d54a0cdc38d2e26394759541ad6f5d5b5
crc32: E2D98902
md5: 0a72ed7f43b19d4e33c811f897a494d4
sha1: d3664d76e7d1b453b17c55828742f3a05d75cfe8
sha256: 97dc9ff9fbd1c7dc9b9ba46491fc021d54a0cdc38d2e26394759541ad6f5d5b5
sha512: a21e77d5546c1d5fa80c082bd14078384660f5d94bdd5c977364049ac34b91512515a0e28231035ea4b11616200c2dd59ae7c5e646835c476e73a43bea9f1c87
ssdeep: 98304:Q4wFYuXecRBpjPZuv24Wyx6L1fIkUOC6A:Q43uOCJP4+4WO6LCc
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10DE53344B516CB87F0CD63F6EC635CFEE2CA39C4ABA9B94806D2C4E92448175B7CD41A
sha3_384: eeb05704b72aecb6ee6b72c7efbed538c92b70700a43378d98f48d49424757cd16f3b3175caba5002208a30ca2d2bfb1
ep_bytes: ba0000000050683d0902155901ff5b81
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.29455 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.29455
FireEyeGeneric.mg.0a72ed7f43b19d4e
ALYacGen:Variant.Fragtor.29455
MalwarebytesTrojan.Crypt.UPX
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Fragtor.29455
K7GWTrojan ( 0058c5ff1 )
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderThetaGen:NN.ZexaF.34182.epZ@aaFtWfg
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
AvastWin32:CoinminerX-gen [Trj]
KasperskyVHO:Trojan.Win32.Copak.gen
RisingTrojan.Kryptik!1.D12D (RDMK:cmRtazqaraCREVFSHF7Cl3nCSVGz)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Fragtor.29455 (B)
APEXMalicious
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68C
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.29455
CynetMalicious (score: 100)
McAfeeGenericRXAA-FA!633EE1596C8B
VBA32Trojan.Packed
CylanceUnsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Coinminer.yi
MAXmalware (ai score=82)
MaxSecureVirus.Sality.AA
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.6e7d1b

How to remove Fragtor.29455 (B)?

Fragtor.29455 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment