Malware

Fragtor.47195 (B) removal tips

Malware Removal

The Fragtor.47195 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.47195 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Bolivia)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Fragtor.47195 (B)?


File Info:

name: E79BEEAD03621356AD3E.mlw
path: /opt/CAPEv2/storage/binaries/687952882fa0e12d702a2ba36c7973d38f07d68966d86dabda3a961764c62f2f
crc32: 4529AB56
md5: e79beead03621356ad3e4a31261958e9
sha1: 1b03aeaa5a8fbf291e7a4b91c4f14a158ba894ec
sha256: 687952882fa0e12d702a2ba36c7973d38f07d68966d86dabda3a961764c62f2f
sha512: dd1b55a51f03e3453c9a5de5ea322adc31f9f1bd382120d446942cf966289e26d3bf2b25514adf6b382b983c1ccd2326785cea5d501eb0a3f9153293c22ce7bb
ssdeep: 6144:vUIbB0B2hW/eZnL61UGakWs1ujKnK/jrwhCPXMw:vU8RhWoL61CkWsKKn0m1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D94D01136C1C072C09765BA8C19CBB15EAA74712B265ACFBFC94BB99F247C1DB2530E
sha3_384: 9b2b529e2df0c01acf3218009ff43ac733c44c9aecafdbbde500c480e902bdca7b782dd783d723200dd9efd62fcc47dc
ep_bytes: e80b620000e978feffff8bff558bec83
timestamp: 2021-01-08 16:46:40

Version Info:

FileVers: 7.0.4.24
ProductVersa: 7.0.25.71
InternalName: reaLatimad
LegalCopyrighd: Jdfglsdffa
Translations: 0x0169 0x0301

Fragtor.47195 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.47195
FireEyeGeneric.mg.e79beead03621356
McAfeeArtemis!E79BEEAD0362
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWHacktool ( 700007861 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZexaF.34062.zq0@aaCdygJ
CyrenW32/Kryptik.FWZ.gen!Eldorado
SymantecPacked.Generic.620
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Fragtor.47195
Ad-AwareGen:Variant.Fragtor.47195
EmsisoftGen:Variant.Fragtor.47195 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosML/PE-A
APEXMalicious
GDataGen:Variant.Fragtor.47195
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
IkarusTrojan.Win32.Crypt
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazp4+/VQYqg2avXCJWPVAJb2)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_89%
Cybereasonmalicious.a5a8fb
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.47195 (B)?

Fragtor.47195 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment