Malware

Fragtor.103099 (file analysis)

Malware Removal

The Fragtor.103099 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.103099 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Fragtor.103099?


File Info:

name: 090B53AB578D42E161A5.mlw
path: /opt/CAPEv2/storage/binaries/3dcbf2ee94ac002a9579707d737df9647956fe53a20fa611d493e0bbf92a0822
crc32: B4530988
md5: 090b53ab578d42e161a5e2875a522ae8
sha1: 22822b894d3d8ae1ca9b339e493563ee65a2094d
sha256: 3dcbf2ee94ac002a9579707d737df9647956fe53a20fa611d493e0bbf92a0822
sha512: 445089bdb2b8a5d1fa82d9ae5e44bd092cdda9c520cdc69fd90db078055722c94b8e6681017c29a56139a6c0799b08c003980748048d0eac12630d4cbaf40f5f
ssdeep: 3072:SZ9ZC98jNnLaJJf1feMt1WfoZ9hm4Z+5iKwSlWFIpQyfIN:SZS98j8XFeMvaiZZ1MlXI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1243916B3A1943BD1732A358D5B86A45836BD603E34DC462BE03D4D6FB9B827837363
sha3_384: 1ed492b6c2f6d9fb4e6e13602883df25c21e8bb9a37bb2cbf2d3aac07f0267a6c1d170c9a2143cb2751ac4a836ec13eb
ep_bytes: 60be00b043008dbe0060fcffc787a450
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Fragtor.103099 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Renamer.lxff
MicroWorld-eScanGen:Variant.Fragtor.103099
ClamAVWin.Trojan.Agent-36081
FireEyeGeneric.mg.090b53ab578d42e1
ALYacGen:Variant.Fragtor.103099
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.1652679
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Renamer.331c9fb6
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.94d3d8
BaiduWin32.Worm.Autorun.i
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fragtor.103099
AvastWin32:Dropper-NYO [Drp]
TencentWorm.Win32.Autorun.aee
SophosMal/Generic-S
F-SecureMalware.W32/Renamer.oald
DrWebWin32.HLLW.Autoruner.26228
VIPREGen:Variant.Fragtor.103099
TrendMicroTROJ_GEN.R002C0DGU23
McAfee-GW-EditionBehavesLike.Win32.RealProtect.dt
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Fragtor.103099 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.103099
AviraW32/Renamer.oald
Antiy-AVLTrojan/Win32.Unknown
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Fragtor.D192BB
MicrosoftTrojan:Win32/Dorv.A!rfn
GoogleDetected
AhnLab-V3Win-Trojan/Autorun.Gen
McAfeeGenericRXAA-AA!090B53AB578D
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGU23
RisingWorm.Win32.Agent.iqk (CLASSIC)
IkarusTrojan-Dropper.Agent
MaxSecureWorm.Win32.AutoRun.gzzs
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36348.nmW@a4nsDZob
AVGWin32:Dropper-NYO [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Fragtor.103099?

Fragtor.103099 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment