Malware

Should I remove “Fragtor.51200”?

Malware Removal

The Fragtor.51200 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.51200 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers

How to determine Fragtor.51200?


File Info:

name: 4A801EB2B60129508040.mlw
path: /opt/CAPEv2/storage/binaries/b130042a45d75377436757e3b0bd6156d950cc611e35e654ae308ff9789e1c35
crc32: 6F1EAAB5
md5: 4a801eb2b6012950804003ee9b0914cf
sha1: c5e598431676fbb484ed27f36484f49ed11baa62
sha256: b130042a45d75377436757e3b0bd6156d950cc611e35e654ae308ff9789e1c35
sha512: 7dd2cca5e3f90e4e07670a748a617669eec8d43836405b7adbf8ab1dd2b26ef3d6bce8f1f04fa2abbc5bb7f8a010dbf199d79289a489cf61d9cc96c28a0c262b
ssdeep: 98304:EZBARHGb3w434q/CZeoN+vUz3lqYmr69Q30D+N+T8GLsxYuRA39KWJ2V:E8zq/Cb9z1lQ30Y+T8GLsauOJJm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10C5623672225124DE1D5C83C8A37FDF436F2227BAA42ACFD85DF69C627174A0D213A53
sha3_384: 21c4eb9ee393fc5136c8891eeaed44a773794645fced2ae4288ea98ea9834bc42c37540e41c25bcbc5043c6ec032bd9c
ep_bytes: 683d52fc58e8570cb8fff5f7c7325c80
timestamp: 2022-02-07 10:33:44

Version Info:

0: [No Data]

Fragtor.51200 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Gamehack.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.51200
FireEyeGeneric.mg.4a801eb2b6012950
ALYacGen:Variant.Fragtor.51200
CylanceUnsafe
SangforRiskware.Win32.Gamehack.vho
K7AntiVirusTrojan ( 7000001c1 )
AlibabaRiskWare:Win32/VMProtect.3b40504d
K7GWTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZexaF.34232.@FW@aiAkjlni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.XK
TrendMicro-HouseCallTROJ_GEN.R03BC0RBH22
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Disco.kvf
BitDefenderGen:Variant.Fragtor.51200
AvastWin32:Trojan-gen
TencentWin32.Trojan-qqpass.Qqrob.Peps
Ad-AwareGen:Variant.Fragtor.51200
EmsisoftGen:Variant.Fragtor.51200 (B)
TrendMicroTROJ_GEN.R03BC0RBH22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosMal/VMProtBad-A
IkarusPUA.GameHack
GDataGen:Variant.Fragtor.51200
AviraHEUR/AGEN.1200255
Antiy-AVLTrojan/Generic.ASMalwS.352490A
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Fragtor.DC800
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R468051
McAfeeArtemis!4A801EB2B601
MAXmalware (ai score=84)
APEXMalicious
RisingMalware.Strealer!8.1EF (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Application
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.140080724.susgen

How to remove Fragtor.51200?

Fragtor.51200 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment