Malware

Fragtor.386429 removal instruction

Malware Removal

The Fragtor.386429 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.386429 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Fragtor.386429?


File Info:

name: C9DC399500C4B8BBF015.mlw
path: /opt/CAPEv2/storage/binaries/de9954a4f8bbf0c50edbf5056e4b40716b6a0e01ab883a6ed1ecbebf88fd61e9
crc32: 780DB2A7
md5: c9dc399500c4b8bbf0153e08d3f2c912
sha1: 30b6e842d62e15fb25407180d9489cd4dc616cd4
sha256: de9954a4f8bbf0c50edbf5056e4b40716b6a0e01ab883a6ed1ecbebf88fd61e9
sha512: ed975709f039e565f018d3a67fabfca98d815907e52c445e6c49c44fecb72549edcbd1c162549d323e7a9fbd6caeb7a17ddef75ae117a179dd4643850eef9416
ssdeep: 196608:EOOFKFtt3JEzJsXADNkCtMxzJfRp0DT9xL:Ex8tqmwDN+xTY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1287633B362651082D5E1CC3A902B7EE4B1F703D98A01DCB95997BDC12E358EBE727643
sha3_384: ce539818e62460f6cc1ddc28139c020f39532c9aa2838c57d46e57548b4d17f7cb915616c4f98c71369a6eec7a9efec4
ep_bytes: e83b7ccfff660fb60ef6d28a5602f93b
timestamp: 1971-10-21 09:26:40

Version Info:

FileDescription: zxbg.exe
FileVersion: 2.0.18.0
ProductVersion: 2.0.18.0
LegalCopyright: 版权所有 国家信息安全工程技术研究中心 保留所有权利
OriginalFilename: zxbg.exe
ProductName: 在线变更
InternalName: zxbg.exe
Translation: 0x0804 0x04b0

Fragtor.386429 also known as:

BkavW32.Common.2E84D105
CyrenCloudRisk/WIN_PE.de9954a4!Threatlookup
LionicTrojan.Win32.VMProtect.4!c
MicroWorld-eScanGen:Variant.Fragtor.386429
FireEyeGeneric.mg.c9dc399500c4b8bb
SkyhighBehavesLike.Win32.Generic.wc
McAfeeGenericRXAA-AA!C9DC399500C4
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.VMProtect.Win32.86335
SangforTrojan.Win32.Fragtor.Vm93
K7AntiVirusTrojan ( 0059f3ca1 )
K7GWTrojan ( 0059f3ca1 )
ArcabitTrojan.Fragtor.D5E57D
VirITTrojan.Win32.Genus.UKA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AU suspicious
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Fragtor.386429
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:MalwareX-gen [Trj]
Ad-AwareGen:Variant.Fragtor.386429
EmsisoftGen:Variant.Fragtor.386429 (B)
F-SecureTrojan.TR/Redcap.ftwlx
VIPREGen:Variant.Fragtor.386429
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraTR/Redcap.ftwlx
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fragtor.386429
BitDefenderThetaGen:NN.ZexaF.36608.@Z0@aaia51mi
ALYacGen:Variant.Fragtor.386429
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09JF23
YandexRiskware.VMProtect!aOD4kwqJ75g
IkarusPUA.VMProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Fragtor.386429?

Fragtor.386429 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment