Malware

Fragtor.102856 removal guide

Malware Removal

The Fragtor.102856 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.102856 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.102856?


File Info:

name: 8A8B61098B339BCF7797.mlw
path: /opt/CAPEv2/storage/binaries/4eaa616363547e59ace04cdd800f0505fdcc294b7c990eb73c1a67a5b7254690
crc32: D66C55FA
md5: 8a8b61098b339bcf7797788d7afda783
sha1: feb5e58807cf67113dc3064db811afb152fbee52
sha256: 4eaa616363547e59ace04cdd800f0505fdcc294b7c990eb73c1a67a5b7254690
sha512: 98099c5289827be53809c3062691de77e1bbfa3b3c5f431ae2c75a147b0a6c83c3e3f7ccc2c6ed9e233b68a19a238f50c0b0db84c21876ccc8773d1e507791a1
ssdeep: 768:qurTfbKc9xjXvKBBW5bu33XwDqkUvCpQY:qu+cDjSBBWEnXwDqdvCt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T194C28E97F5C28871CF5509F12172FEB889BFB5302CAAAA524750F72669EB1B0D50808F
sha3_384: 5fdaf1f0d2c98545e6bfc4523b7d507d9f2c90c496dcdfb9247ee42312fa42dabbd27346659c1b7fe6bf0e73c0d13689
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.102856 also known as:

DrWebTrojan.MulDrop20.10627
MicroWorld-eScanGen:Variant.Fragtor.102856
ALYacGen:Variant.Fragtor.102856
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.98b339
CyrenW32/Agent.ENB.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.102856
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.102856
TACHYONTrojan/W32.Fugrafa.26112
EmsisoftGen:Variant.Fragtor.102856 (B)
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!8A8B61098B33
FireEyeGeneric.mg.8a8b61098b339bcf
SophosTroj/PWS-CMJ
IkarusTrojan.DelFiles
GDataGen:Variant.Fragtor.102856
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
ArcabitTrojan.Fragtor.D191C8
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
McAfeeGenericRXNV-VM!8A8B61098B33
MAXmalware (ai score=84)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fragtor.102856?

Fragtor.102856 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment