Malware

Fragtor.22424 removal

Malware Removal

The Fragtor.22424 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.22424 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.22424?


File Info:

name: 9492F37A3E8FF8177F42.mlw
path: /opt/CAPEv2/storage/binaries/a43d22aeb7b8357fd46e3cc92561932d4198c1cd6352638fb152abac8f84941a
crc32: 2F3FC25A
md5: 9492f37a3e8ff8177f424586cd32a898
sha1: d6cac41c8cee9d918ea50ec8c1b15cf38fb5d567
sha256: a43d22aeb7b8357fd46e3cc92561932d4198c1cd6352638fb152abac8f84941a
sha512: 976f04fd1f39be9a3df7d8523ae84dec9ba83806cd384b766d5f4bd1237a9a34298365b4c9df6d80917cab42b584294790fe19a9598dfa67cee91a693fbf7bb9
ssdeep: 24576:8CrOKRx4PO/PAKWzVy5GRXM23sT9W8SPiRk:fPRWm/Pe8fW78S
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18505235E1ECFA3FBD5D055BB25F14B6932E29BFD012D27DA22132D9C2087560B8F5888
sha3_384: 32afc11fb1e56565df35d18b3a1f17ad12c3ead36441c371aea12a74afb3afa2fc19a2b4a9bcffd1bd4644211c5578fe
ep_bytes: b8000000005681c3010000004389db8b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.22424 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Fragtor.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.22424
FireEyeGeneric.mg.9492f37a3e8ff817
McAfeeGenericRXOS-KI!9492F37A3E8F
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aKj8eZd
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Copak
BitDefenderGen:Variant.Fragtor.22424
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosML/PE-A + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroTROJ_GEN.R002C0DAT22
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Fragtor.22424 (B)
IkarusTrojan.Win32.Injector
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68C
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.22424
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R364268
VBA32Trojan.Packed
ALYacGen:Variant.Fragtor.22424
MAXmalware (ai score=82)
MalwarebytesTrojan.Crypt.UPX
TrendMicro-HouseCallTROJ_GEN.R002C0DAT22
RisingTrojan.Kryptik!1.D238 (CLOUD)
YandexTrojan.Kryptik!SrfKWYZBsEo
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.c8cee9
PandaTrj/Genetic.gen

How to remove Fragtor.22424?

Fragtor.22424 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment