Malware

Fragtor.89640 removal instruction

Malware Removal

The Fragtor.89640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.89640 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Fragtor.89640?


File Info:

name: 2F6B1EAAB3604FA46502.mlw
path: /opt/CAPEv2/storage/binaries/4a96af19d57394ee5b8f2c6d7b882dcf73d7d07ef3820125acc87a67eaf39bb4
crc32: F64FC37F
md5: 2f6b1eaab3604fa46502399da41d9664
sha1: 7ced58baff58daee9fe7c99601324e093919f725
sha256: 4a96af19d57394ee5b8f2c6d7b882dcf73d7d07ef3820125acc87a67eaf39bb4
sha512: ae59d2cda6e63464c171c12ffed8fbfbd6791e32b8972ca46e2ad9db393dd1ec7c6b3ce8833208c679f585ddc34078b85cf1cd761ec854ace210589c41263e50
ssdeep: 24576:7066pwbFptOdTgKqjlkCdajOIlPCQhBks8aMw09q6a8IBc:6pwbJMqjyCEn9zFzMnKo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C4523E3D5D00695E11161B1B5939D4D8BAECE9688F9CC0C2622F8AC5FF8EE040E5F76
sha3_384: b5bee96da89dbb9ae1e5d74b5bd8b535e2e0d413fab6d7c4bb1b08f48d12d582ecafbf54894a86ce0f79f1b35ff82003
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2022-05-12 07:14:40

Version Info:

FileVersion: 1.0.0.0
FileDescription: 极客
ProductName: 极客脚本
ProductVersion: 1.0.0.0
CompanyName: JK
LegalCopyright: JK 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Fragtor.89640 also known as:

LionicAdware.Win32.Agent.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.89640
FireEyeGeneric.mg.2f6b1eaab3604fa4
McAfeeArtemis!2F6B1EAAB360
CylanceUnsafe
AlibabaAdWare:Win32/Flyagent.36aaf164
K7GWAdware ( 005848221 )
K7AntiVirusAdware ( 005848221 )
CyrenW32/OnlineGames.HG.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Fragtor.89640
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Fragtor.89640
EmsisoftGen:Variant.Fragtor.89640 (B)
ZillyaAdware.Agent.Win32.172703
TrendMicroTROJ_GEN.R002C0PEH22
McAfee-GW-EditionBehavesLike.Win32.Autorun.tc
Trapminemalicious.high.ml.score
SophosGeneric PUA HM (PUA)
JiangminAdware.Agent.aveb
KingsoftWin32.Heur.KVM099.a.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Application.PUPStudio.A
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Agent.R487959
BitDefenderThetaGen:NN.ZexaF.34742.hD0baOFWW9ib
ALYacGen:Variant.Fragtor.89640
MAXmalware (ai score=85)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.3744262475
TrendMicro-HouseCallTROJ_GEN.R002C0PEH22
RisingAdware.Agent!8.71 (TFE:dGZlOgWYN9nKye3QPA)
IkarusTrojan.Win32.Themida
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Flyagent
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.aff58d
PandaTrj/CI.A

How to remove Fragtor.89640?

Fragtor.89640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment