Malware

How to remove “Fragtor.26500”?

Malware Removal

The Fragtor.26500 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.26500 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.26500?


File Info:

name: F16EA5327F1CBEAA3B47.mlw
path: /opt/CAPEv2/storage/binaries/3fd547fa48c8ff260e3f4b1e33dfd9977a8454cc9146d11c7ec0d3920c78b946
crc32: 6BC77E63
md5: f16ea5327f1cbeaa3b4732dba386f2f9
sha1: 57d3ee9c109f60ef65bcb2a440b057d72511ec24
sha256: 3fd547fa48c8ff260e3f4b1e33dfd9977a8454cc9146d11c7ec0d3920c78b946
sha512: 2f1a0818e510a4e5277689707bc2aa83da50c7f3364ebe14e4d4890401aa90096d48a3f6bba30e84b17a8c8ca86823d420bcdd8bab7f4961fa40c3da32178ee7
ssdeep: 12288:xyOetJl3hGG5Go66IzLH1Und/Y2ZomUizu+/yCeRCoYrqBIWUry6uPdMHQX99C59:xedZUVUndymUizu+1rqBIFryBPaHmf
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T122053359BD3A3885E05D0EF38386F9338C4345B5267EBE161A53DC8EC1B2852F24AED5
sha3_384: 3e694846fa35c6e7d5bc1bb548707f8a969619df4df5ebe4032fed4125d07ed5b27cee815c4fd18a85ed861d6428e535
ep_bytes: b8000000005121d25f89f681c6d076c5
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.26500 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.26500
FireEyeGen:Variant.Fragtor.26500
ALYacGen:Variant.Fragtor.26500
CylanceUnsafe
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 005762bf1 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.26500
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.26500
EmsisoftGen:Variant.Fragtor.26500 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/HckPk-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.26500
JiangminTrojan.Copak.azvf
eGambitUnsafe.AI_Score_87%
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C68D
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
McAfeeGenericRXAA-FA!F16EA5327F1C
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazr0ttabofkfkgYI8XdYH1WS)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Fragtor.26500?

Fragtor.26500 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment