Malware

Fragtor.159539 (file analysis)

Malware Removal

The Fragtor.159539 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.159539 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.159539?


File Info:

name: 16064A8D3B2159D07F3D.mlw
path: /opt/CAPEv2/storage/binaries/3e58676d343563495e437c0a2a8ee99af09890b21053041be336b7db6b6ab3c0
crc32: F5B65B82
md5: 16064a8d3b2159d07f3d139b06ff419a
sha1: 86c14c047fe8a9a61bfe3443ad8a00016931273c
sha256: 3e58676d343563495e437c0a2a8ee99af09890b21053041be336b7db6b6ab3c0
sha512: affccc0e53c4b8a72ce2f114d1731a356f184e4f8a0473e11ec06ee9e7941f4910d046a8ec53acd547f88630f9a01d16e189a6befcd105c1d515e98b64e4991d
ssdeep: 3072:BoWWQPq1qCC9jMPTOYvk39dEvS4uBA2n:BoWZoqCcjKvk34vSlS2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T195C3023EA5415CA2CF493438E4E45E88212C2DD9FE94E9401AF4C71BEF7E217B358B66
sha3_384: 4ffca2b858798aa782da463b01eabc5d50217cd8054d580e40c73cbd22815a6395685a557b9547fe3f5209023cc83040
ep_bytes: 60beff8be63ef7d64161f7d109c921f6
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.159539 also known as:

AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.159539
FireEyeGeneric.mg.16064a8d3b2159d0
McAfeeGenericRXVB-MY!16064A8D3B21
Cylanceunsafe
VIPREGen:Variant.Fragtor.159539
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
K7GWTrojan ( 0057fe481 )
BitDefenderThetaGen:NN.ZexaF.36308.hmW@aeTLZM
CyrenW32/Injector.AGA.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.EBQH
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Fragtor.159539
NANO-AntivirusTrojan.Win32.Copak.jtxgfo
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.ka
TACHYONTrojan/W32.Copak.125440.P
EmsisoftGen:Variant.Fragtor.159539 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SophosML/PE-A
IkarusTrojan.Spy.Agent
GDataWin32.Trojan.PSE.1M9NXCV
JiangminTrojan.Copak.clgo
AviraHEUR/AGEN.1200606
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Fragtor.D26F33
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Evo-gen.R542946
Acronissuspicious
VBA32Trojan.Copak
ALYacGen:Variant.Fragtor.159539
MAXmalware (ai score=85)
MalwarebytesTrojan.Dropper.UPX
RisingTrojan.Injector!1.E280 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.115533306.susgen
FortinetW32/GenKryptik.CRNJ!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.159539?

Fragtor.159539 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment