Malware

Fragtor.484604 removal tips

Malware Removal

The Fragtor.484604 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.484604 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Fragtor.484604?


File Info:

name: D7748D5C884A4E0C331A.mlw
path: /opt/CAPEv2/storage/binaries/70fd04d1673dd0c76017fb90bdb3f77e9a81cd09f98ea7b7c1e89ace340c8794
crc32: EAD13351
md5: d7748d5c884a4e0c331a568997f9d8bb
sha1: 0510993be6b3d9b42942fef4fd05e793beba0004
sha256: 70fd04d1673dd0c76017fb90bdb3f77e9a81cd09f98ea7b7c1e89ace340c8794
sha512: 5010886add5e4b3f7212a6816aa23ea46f3cee47c2419788faf96173fab4e6f0f496d9f7222e838bd67020d92fa4410cd9b22a5ea9fe3efe2c08a8a6069f758c
ssdeep: 49152:cy6HNFj/kggwfGgggfvbzAZz744yMtAwQA43U+kwwMw+r7EcPnK:c3HX7TgwfGAfvbzAJ744yMtAwQA43U+x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8A56C21355742B7E32306319AEDF279F1ACB5F02B2A41C762E5DB2C29755824A3C63F
sha3_384: fba4e7f7d1f951c4abde9de98cfb40e91c0bc043dff3383c03f11e5aac3e6d768a0da044676d8d6a99f8d5adf3dda9c5
ep_bytes: e8a00d0000e97afeffff3b0d00905f00
timestamp: 2024-01-04 03:04:57

Version Info:

CompanyName:
FileDescription:
FileVersion: 0.0
InternalName: d
LegalCopyright:
OriginalFilename: d.exe
ProductName:
ProductVersion: 0.0
Translation: 0x0804 0x04b0

Fragtor.484604 also known as:

BkavW32.Common.40940A5B
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Fragtor.484604
FireEyeGen:Variant.Fragtor.484604
SkyhighBehavesLike.Win32.Dropper.vh
ALYacGen:Variant.Fragtor.484604
Cylanceunsafe
SangforTrojan.Win32.SilverFox.swkam
K7AntiVirusAdware ( 005a0d081 )
K7GWAdware ( 005a0d081 )
BitDefenderThetaGen:NN.ZexaF.36744.iw0@aKO0zLgj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.BO potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fragtor.484604
AvastWin32:MalwareX-gen [Trj]
RisingPUF.Agent!8.1B6B (TFE:5:nDebHCpQZdR)
SophosGeneric Reputation PUA (PUA)
VIPREGen:Variant.Fragtor.484604
EmsisoftGen:Variant.Fragtor.484604 (B)
GDataGen:Variant.Fragtor.484604
Antiy-AVLGrayWare/Win32.Agent
ArcabitTrojan.Fragtor.D764FC
MicrosoftPUA:Win32/Puwaders.C!ml
McAfeeGenericRXAA-AA!D7748D5C884A
MAXmalware (ai score=84)
MalwarebytesPUP.Optional.ChinAd
TrendMicro-HouseCallTROJ_GEN.R03BH09AK24
IkarusPUA.Agent
MaxSecureTrojan.Malware.223467307.susgen
FortinetRiskware/Agent
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Fragtor.484604?

Fragtor.484604 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment