Malware

Fragtor.179256 removal guide

Malware Removal

The Fragtor.179256 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.179256 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.179256?


File Info:

name: 09600D155B3D1879ECFA.mlw
path: /opt/CAPEv2/storage/binaries/63883a064cc0ba8af6b6913a6c756ca0f8c726983e1b3be87326f13acb35eaf5
crc32: B68F2C3C
md5: 09600d155b3d1879ecfa07ebfeacd25d
sha1: 7d3fedc1b30ac7f109b3a09924f6c305d8c7f56e
sha256: 63883a064cc0ba8af6b6913a6c756ca0f8c726983e1b3be87326f13acb35eaf5
sha512: 6908d42fe26af2a361cf6eb7c55b9c615cce464b968b1c79a683ef7bfa4e6fc86943becbf82c9de007122c8c9e1e9a3d36a302c8e1a96b543e482350b50c826c
ssdeep: 3072:CQZBE3Or3D3st130V2zdOi3Wd0wQ6FWJWD:XnE6c0GOfW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F4C3029EC9902F1FCF5B247E48865817781CE1B37135C1043D62E8A853FEA97B7E18A1
sha3_384: 5c580a37af5d1cc8410a5012da1aadfa63e772e5ec7830d85809cb19bc40af45e0a2bbbf4f78523723a013d9048b5671
ep_bytes: 60bee1fe470e29da29d36101da81eb20
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.179256 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fragtor.179256
ALYacGen:Variant.Fragtor.179256
MalwarebytesTrojan.Dropper.UPX
VIPREGen:Variant.Fragtor.179256
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
K7GWTrojan ( 0057fe481 )
ArcabitTrojan.Fragtor.D2BC38
BitDefenderThetaGen:NN.ZexaF.36318.hmW@aeTLZM
CyrenW32/Injector.AGA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.EBQH
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Fragtor.179256
NANO-AntivirusTrojan.Win32.Copak.jtvujr
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.ka
TACHYONTrojan/W32.Copak.125440.BB
EmsisoftGen:Variant.Fragtor.179256 (B)
F-SecureHeuristic.HEUR/AGEN.1333434
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.09600d155b3d1879
SophosML/PE-A
IkarusTrojan.Spy.Agent
JiangminTrojan.Copak.cnbr
GoogleDetected
AviraHEUR/AGEN.1333434
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Copak.vho
GDataGen:Variant.Fragtor.179256
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Evo-gen.R542946
Acronissuspicious
McAfeeGenericRXAA-FA!09600D155B3D
MAXmalware (ai score=83)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.E280 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.179256?

Fragtor.179256 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment