Malware

Fragtor.440602 removal tips

Malware Removal

The Fragtor.440602 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.440602 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.440602?


File Info:

name: D5C54B179FA20F2D4FA1.mlw
path: /opt/CAPEv2/storage/binaries/876aceb76f53889388ff6af28cb7ab1740647b3e8bad0b4b385f30fc1b2be5b0
crc32: 0AE4EFEC
md5: d5c54b179fa20f2d4fa1938e6e55ec96
sha1: f2d919d283b08fe9cbc802bdad1a43e36990e41d
sha256: 876aceb76f53889388ff6af28cb7ab1740647b3e8bad0b4b385f30fc1b2be5b0
sha512: 2973937e1163735eadc57aab6470e4954aafb73cf92a5ee8c0dc96c79a4ff0348d33ba244d6e018b04be67b8369f75d9139797beac445e34cc6732a3645e5389
ssdeep: 196608:5miE3heROgKJ8MfamxH8TRPWeWRDPmOD2h88DIh+sGxEYT:5esBKJ8/mwRPWHROY2XD68xjT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11FA633BA9C618480DF24C476A57B8F39B35A61F4106BE73B4F6311DB16CFAC969E1103
sha3_384: 191d39a713d6b5be20a34121d611aa159c887a258629a5f1ce90ce4b4f3726045ff5eb4fe6922ead0cea1547195d207f
ep_bytes: 6801d08300e801000000c3c348fb90ef
timestamp: 2013-01-30 05:35:35

Version Info:

FileVersion: 1.0.2.4
FileDescription: rxjh Game Launcher
ProductName: Mom GameSoft
ProductVersion: 1.0.2.4
CompanyName: Mom GameSoft
LegalCopyright: Mom GameSoft
Comments: Mom GameSoft
Translation: 0x0804 0x04b0

Fragtor.440602 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Click2.25931
MicroWorld-eScanGen:Variant.Fragtor.440602
FireEyeGeneric.mg.d5c54b179fa20f2d
SkyhighBehavesLike.Win32.Generic.tc
ALYacGen:Variant.Fragtor.440602
K7AntiVirusUnwanted-Program ( 0056626f1 )
K7GWUnwanted-Program ( 0056626f1 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Fragtor.D6B91A
BitDefenderThetaGen:NN.ZexaF.36792.@B3aaaBuPHlb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fragtor.440602
AvastWin32:Evo-gen [Trj]
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Fragtor.440602
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fragtor.440602 (B)
SentinelOneStatic AI – Suspicious PE
GoogleDetected
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Fuerboos
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Fragtor.440602
VaristW32/OnlineGames.HI.gen!Eldorado
McAfeeGenericRXES-CK!D5C54B179FA2
VBA32BScope.TrojanPSW.Zbot
Cylanceunsafe
YandexTrojan.GenAsa!YjTPMX5Pm/Y
IkarusTrojan-PWS.Win32.Delf
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.283b08
DeepInstinctMALICIOUS

How to remove Fragtor.440602?

Fragtor.440602 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment