Malware

Fragtor.105894 (B) removal instruction

Malware Removal

The Fragtor.105894 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.105894 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.105894 (B)?


File Info:

name: 9171008A940C9AD8E087.mlw
path: /opt/CAPEv2/storage/binaries/41f6d30f76ba1005218d67dd039e06802c2673bc4cccd7104f481baabe4837c3
crc32: 619883EB
md5: 9171008a940c9ad8e087f49b783b1279
sha1: 18753af40c494b34e8bcfcf03db37db269f863a7
sha256: 41f6d30f76ba1005218d67dd039e06802c2673bc4cccd7104f481baabe4837c3
sha512: 28edb24d08781cf9cba43d708ce37944401d7637d871ee1daef7221a96742d6b8eaf028244b08cd4cda871134e7638ad735a4b4a5cc7f2fb88092f7c696b8a26
ssdeep: 384:eWS76SFRG6BXcjUx9veEh09RXjXz7XjCWwqK8Wzz8WW5bIwHMxnpGggekSaKiQAz:1SlFRBXb89xjXvKBBW5b+Hg3Sti7b
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T142C29D43EA968971DFE005B551B7BEB9C6FFFF200931E6D1AF10ED0A0DA6010B22615E
sha3_384: 0cac5e2298eebc77a0c45c991a3690821a3030994c6328ef7e5daef8e35066f85eb657c76aebf05c706a36f90fd0ae7c
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.105894 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.105894
FireEyeGeneric.mg.9171008a940c9ad8
McAfeeGenericRXNV-VM!9171008A940C
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.a940c9
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OOO
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.105894
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.105894
SophosTroj/PWS-CMJ
DrWebTrojan.MulDrop20.10627
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!9171008A940C
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Fragtor.105894 (B)
APEXMalicious
GDataGen:Variant.Fragtor.105894
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MAXmalware (ai score=87)
ArcabitTrojan.Fragtor.D19DA6
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Fragtor.105894
TACHYONTrojan/W32.Fugrafa.26112
MalwarebytesMalware.AI.2397151589
RisingStealer.Agent!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fragtor.105894 (B)?

Fragtor.105894 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment