Malware

Fragtor.29099 removal instruction

Malware Removal

The Fragtor.29099 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.29099 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • CAPE detected the Alfonoso malware family
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

How to determine Fragtor.29099?


File Info:

name: 0C019262753944965678.mlw
path: /opt/CAPEv2/storage/binaries/37b697e1d91ea894dec3e202a5c4ef951997b5f3772e63330c50b705c6dcede0
crc32: C66A0B00
md5: 0c019262753944965678f46b4ba8585b
sha1: 148a34be3a61bfe0596f663240ea4b6aabfa29a7
sha256: 37b697e1d91ea894dec3e202a5c4ef951997b5f3772e63330c50b705c6dcede0
sha512: 33e2b898527b50fe65beec75f4315c80081ee12ba0c13dda835e04e05e8ca283022becf8039a59edac15e8f01af320881f0b8f048ddbf20060878fb839e0b005
ssdeep: 12288:QokfGiD8pdNn9KCT7tDlWCXJq7C7HtyyU9lbALDa/p9ZpiD:QoCDMNn9KCf1lWCXJWC7hU9lq4k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137C4BE0BE6429076E4632430229D8F6698BD763049236577B7C42D2D5EB01F2EB36F77
sha3_384: 91b1a2ba50fb72238711e8201d8dcb8c161d54bb101dcd6eca611f60ddca4b0e68bb3d45939ee4807772ce4d51e2bfb3
ep_bytes: e884040000e974feffff558bec81ec24
timestamp: 2022-04-17 21:02:57

Version Info:

0: [No Data]

Fragtor.29099 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.29099
FireEyeGeneric.mg.0c01926275394496
ALYacGen:Variant.Fragtor.29099
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.DJJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OKX
APEXMalicious
ClamAVWin.Malware.Zusy-9812688-0
KasperskyHEUR:Trojan-PSW.Win32.Shurk.gen
BitDefenderGen:Variant.Fragtor.29099
AvastWin32:DullStorm-B [Pws]
TencentMalware.Win32.Gencirc.11f10d06
Ad-AwareGen:Variant.Fragtor.29099
EmsisoftGen:Variant.Fragtor.29099 (B)
ZillyaTrojan.Agent.Win32.2766330
McAfee-GW-EditionBehavesLike.Win32.Trojan.hh
SophosGeneric ML PUA (PUA)
IkarusTrojan-PSW.Agent
GDataWin32.Trojan-Stealer.Phoenix.B
AviraHEUR/AGEN.1213248
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3566F95
MicrosoftPWS:MSIL/Phoenix.GG!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Phoenix.C5094321
Acronissuspicious
McAfeeGenericRXSQ-WK!0C0192627539
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingStealer.Agent!8.C2 (C64:YzY0OgW8OOCOjRVurg)
YandexTrojan.PWS.Agent!uLEZElhspcU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34606.IuW@a0WQw3hi
AVGWin32:DullStorm-B [Pws]
PandaTrj/GdSda.A

How to remove Fragtor.29099?

Fragtor.29099 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment