Malware

Fragtor.159042 (file analysis)

Malware Removal

The Fragtor.159042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.159042 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Fragtor.159042?


File Info:

name: 99BD84F7FBC9C5E9CF5E.mlw
path: /opt/CAPEv2/storage/binaries/f8085e2ef9d5e401e5e1f77742f2334aac77e63c50c0e0eb7840afdff9b28333
crc32: 33B27CBF
md5: 99bd84f7fbc9c5e9cf5e9518c0987bb5
sha1: d46b94feaa85ce276a19363aeb694a094cb5fb93
sha256: f8085e2ef9d5e401e5e1f77742f2334aac77e63c50c0e0eb7840afdff9b28333
sha512: 73d55fed82b135dd892a363849b2c0c551ec3ecc0b971945a00d78f1bf18dc2b218881b335bf3fceea1cb99a4f45cfb6259356700bf53e5dd73db35cec1d1417
ssdeep: 98304:d8pOYyhtcnyr8HijecRnl+SjK+hN8B8NWdMJHfNEG7ir8qVU9kHZnRLtg:d8pxyhi8K4emltTClKJHFv7EU9k7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15566BF659380A12BE47E1775562EA68E50B93230D920ACB7F3844F4C7EF5BC1EA2D707
sha3_384: a46bebf5f842be47063a5cc9244012bbb9403123a35cd926a236d73fe88f46f1f92642a1281f6212ea4f0fc8cc4c5540
ep_bytes: 558bec83c4f0b89c65a100e8dc499fff
timestamp: 2022-11-01 06:42:43

Version Info:

0: [No Data]

Fragtor.159042 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.159042
ClamAVWin.Malware.Danabot-9937929-0
FireEyeGeneric.mg.99bd84f7fbc9c5e9
McAfeeArtemis!99BD84F7FBC9
ZillyaTrojan.Danabot.Win32.9011
CrowdStrikewin/malicious_confidence_90% (D)
K7GWSpyware ( 0058eaac1 )
K7AntiVirusSpyware ( 0058eaac1 )
CyrenW32/Danabot.AY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Danabot.U
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Danabot.gen
BitDefenderGen:Variant.Fragtor.159042
AvastWin32:WormX-gen [Wrm]
TencentMalware.Win32.Gencirc.10bda297
Ad-AwareGen:Variant.Fragtor.159042
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Fragtor.159042
McAfee-GW-EditionBehavesLike.Win32.AdwareDealPly.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fragtor.159042 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.8IPIJU
AviraHEUR/AGEN.1249398
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.5821
ArcabitTrojan.Fragtor.D26D42
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R480916
BitDefenderThetaGen:NN.ZelphiF.34784.@VW@aadR8Wb
ALYacGen:Variant.Fragtor.159042
MalwarebytesSpyware.DanaBot
RisingSpyware.Danabot!8.FADB (TFE:5:rCJwNi6dUfL)
YandexTrojanSpy.Danabot!BobyddDwzQk
IkarusTrojan-Dropper.Win32.Danabot
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.eaa85c

How to remove Fragtor.159042?

Fragtor.159042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment