Malware

Fragtor.45844 (B) malicious file

Malware Removal

The Fragtor.45844 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.45844 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Ukrainian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Fragtor.45844 (B)?


File Info:

name: C7417A2A3B587AAD8435.mlw
path: /opt/CAPEv2/storage/binaries/e4194d9884fdeee1dafa1f76237046baf23a781e6ce378c9b020daafd25c0786
crc32: CD4C5E73
md5: c7417a2a3b587aad8435ea6965d372bd
sha1: 8bd7fba4e6d352ea217e71085ff24e32c4051648
sha256: e4194d9884fdeee1dafa1f76237046baf23a781e6ce378c9b020daafd25c0786
sha512: 8c0b39bb3e380030f4b805a43bfdffd1d3d7a559f30f353662615f0ab426ef91162be06e5a69e45dcd221f9eaf1e08171ee346a4165e1acc2b01f7dd1739951d
ssdeep: 24576:IP0gayaYmD9V1SdiOTwOADZS5P/vaedx8dfi5Vfa:IP0gayaDDDO6OF5N
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T169258E22F6C0C437D5B32B79CC5BC1D65429BE242D38AC477AE92F0C5B7968279262C7
sha3_384: 0c8bac10872055ba48dba6e0769e1b70f21042f61761825c773abf360576b72887fdc1ee9993b39634e26efbb8053499
ep_bytes: 558becb9260000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: Click And Deploy (Pte. Ltd.)
FileDescription: AlertDispatcher Console
FileVersion: 8.115.1008.0
InternalName: AlertDispatcher
LegalCopyright: Click And Deploy (Pte. Ltd.)
OriginalFilename:
PrivateBuild:
ProductName: AlertDispatcher
ProductVersion: 8.115.1008.0
Translation: 0x4809 0x04b0

Fragtor.45844 (B) also known as:

MicroWorld-eScanGen:Variant.Fragtor.45844
FireEyeGen:Variant.Fragtor.45844
CAT-QuickHealTrojan.ConvagentIH.S24780604
ALYacGen:Variant.Fragtor.45844
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09KM21
BitDefenderGen:Variant.Fragtor.45844
Ad-AwareGen:Variant.Fragtor.45844
SophosGeneric PUA IL (PUA)
EmsisoftGen:Variant.Fragtor.45844 (B)
Antiy-AVLTrojan/Generic.ASMalwS.34D538D
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Fragtor.970240.A
GDataWin32.Trojan.PSE.1ALBID1
AhnLab-V3Trojan/Win.Generic.C4782226
APEXMalicious
MAXmalware (ai score=89)
FortinetW32/PossibleThreat
PandaTrj/Genetic.gen

How to remove Fragtor.45844 (B)?

Fragtor.45844 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment