Malware

About “Fragtor.36235” infection

Malware Removal

The Fragtor.36235 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.36235 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Fragtor.36235?


File Info:

name: 8BEDF4C4D3816B5E4743.mlw
path: /opt/CAPEv2/storage/binaries/79255b86dc513021d805df5a5b54699d79baa5e5f2c59bf83199eca3160ea630
crc32: E5FD6089
md5: 8bedf4c4d3816b5e47430e178b575f13
sha1: 6054d9879a6a91a64acd07f9c3be3cb2a8f0b43c
sha256: 79255b86dc513021d805df5a5b54699d79baa5e5f2c59bf83199eca3160ea630
sha512: 845530d558f8b3bc8facc9faf55a313ff59021aeaee6153ca061a32375fd2847ef77c75fa96340ad72195ea0b1d3f0761225eb9618139c46f3747b5f99e885a8
ssdeep: 6144:YaPHIPpl/+s3BaMBNDUpqmbnna4JbiDtib9iONa:YOKWs3BaaNDUBn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD747D112AA544B1D65905312524F3F2CA6BED318871EA436BCA7E4F3CF2BC1E684B5F
sha3_384: 86732bee0abfc63807fe4365005ad694ced370cc9ca3582d12323565fc727e98b5de08062fb63c3a022b290c5e06b8e7
ep_bytes: 68b4214000e8eeffffff000000000000
timestamp: 2018-07-01 15:11:25

Version Info:

Translation: 0x0804 0x04b0
CompanyName: FREE
ProductName: fsd
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ZhuRuUDO
OriginalFilename: ZhuRuUDO.exe

Fragtor.36235 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.36235
ALYacGen:Variant.Fragtor.36235
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003d23081 )
AlibabaTrojanSpy:Win32/BScope.b76bc39b
K7GWTrojan ( 003d23081 )
Cybereasonmalicious.4d3816
BitDefenderThetaAI:Packer.1AA7759120
VirITTrojan.Win32.VBZenPack_Heur
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fragtor.36235
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Efbp
SophosMal/Behav-216
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.8bedf4c4d3816b5e
EmsisoftGen:Variant.Fragtor.36235 (B)
IkarusTrojan-Spy.Agent
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.29DC8C7
MicrosoftTrojan:Win32/Tiggre!rfn
GDataGen:Variant.Fragtor.36235
McAfeeArtemis!8BEDF4C4D381
MAXmalware (ai score=99)
VBA32BScope.Trojan.Occamy
APEXMalicious
RisingTrojan.Dynamer!8.3A0 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74261358.susgen
FortinetW32/GenericRXGS.CC!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.36235?

Fragtor.36235 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment