Malware

Fragtor.57889 information

Malware Removal

The Fragtor.57889 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.57889 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Finnish
  • Authenticode signature is invalid
  • Enumerates services, possibly for anti-virtualization

How to determine Fragtor.57889?


File Info:

name: 7D21A9C56A33B494D419.mlw
path: /opt/CAPEv2/storage/binaries/0ec80388167bda82f8c5ec92358580aa080a0d1f729f5e74ef8f4296ab881194
crc32: 5EB2BBEA
md5: 7d21a9c56a33b494d419690c69a380c9
sha1: a3dc1b8718d04bc3a847ec2779b366f22b243371
sha256: 0ec80388167bda82f8c5ec92358580aa080a0d1f729f5e74ef8f4296ab881194
sha512: ed2c065353b8e762ccbf9d98fcc3788a61d5851cce3afeca394effbedba966a0dbf959f9f1b37fd02750b97612f8fca5971b941ddeb1b3328da5d8696956ddfd
ssdeep: 3072:hWgJ8fOL35NZqcI5Khfp4thS5OQeiEgjfCPXIsxkgaBChXHXy3:hWgOOL3HZZhRwcUQe8TCPX1igaQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E454BE10FA90C872C4810E7C9425CBE15A3FBD715A649547F7A8BBAF2F322E06376356
sha3_384: 0b3eaea6c58ed75da4f312a1aa610a215b3eff551902b09c3dababc9d16b0965a2ec3f8b6fcbc5ada3b652314a24e00a
ep_bytes: e863430000e979feffff8bff51c70130
timestamp: 2021-05-10 19:21:31

Version Info:

FileVersion: 21.79.11.69
InternationalName: pomgveoci.iwe
Copyright: Copyrighz (C) 2021, fudkorta
Translations: 0x0127 0x010f

Fragtor.57889 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.57889
FireEyeGeneric.mg.7d21a9c56a33b494
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053d5971 )
K7AntiVirusTrojan ( 0053d5971 )
BitDefenderThetaGen:NN.ZexaF.34182.rq0@a88V3viK
CyrenW32/Agent.EBM.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HOGO
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Fragtor.57889
AvastWin32:CrypterX-gen [Trj]
EmsisoftGen:Variant.Fragtor.57889 (B)
McAfee-GW-EditionPacked-GDT!7D21A9C56A33
SophosML/PE-A + Mal/Agent-AWV
IkarusPacked.Win32.Crypt
MAXmalware (ai score=88)
MicrosoftBackdoor:Win32/Tofsee.MAK!MTB
GDataGen:Variant.Fragtor.57889
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R470642
McAfeePacked-GDT!7D21A9C56A33
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazrk9f1DqDg7Y0F+mLb7sBHg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.57889?

Fragtor.57889 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment