Malware

Should I remove “Fragtor.111317”?

Malware Removal

The Fragtor.111317 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.111317 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.111317?


File Info:

name: C168B1ABFF517FB6753B.mlw
path: /opt/CAPEv2/storage/binaries/bd01c659c80f543b15de086d44144ee7c0103a4d672cd88b1c7578271f7281cb
crc32: 5590B526
md5: c168b1abff517fb6753b92dbc16bd34d
sha1: c238889142010c2f0b30cfc68e75f83b518a47bb
sha256: bd01c659c80f543b15de086d44144ee7c0103a4d672cd88b1c7578271f7281cb
sha512: ecfa3b2f68b02717dcb47b40bfeeec6c902a802e886931f8a11f951fa0c9b7aa5a03195bbcaa63269d2d5734f45e8db0f991817c0c30df84399f970336944151
ssdeep: 384:SWadBuUx98J09RXjXz7XjCWwqK8Wzz8WW5bIwHi4H1du0nfLdhNOtk66c+iu3:Badvb8W9xjXvKBBW5bPfu0c+66NiI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11EC29ECFFAFA4DA1DA9185702632A1718FFFB8683D91E5838F11D5001BE5DB09A1918F
sha3_384: 7e88c24f863f5c841fe3aa21cca95ddeb75cd3b2e79b4e9f6424206b70ca03138569a3a84565261f2fe0b745af2c507b
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.111317 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.111317
FireEyeGeneric.mg.c168b1abff517fb6
CAT-QuickHealTrojan.Stealer.S28360516
ALYacGen:Variant.Fragtor.111317
CylanceUnsafe
ZillyaTrojan.SelfDel.Win32.65008
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.111317
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.111317
TACHYONTrojan/W32.Fugrafa.26112
EmsisoftGen:Variant.Fragtor.111317 (B)
DrWebTrojan.MulDrop20.10627
VIPREGen:Variant.Fragtor.111317
McAfee-GW-EditionGenericRXNV-VM!C168B1ABFF51
SophosTroj/PWS-CMJ
IkarusTrojan.DelFiles
JiangminTrojan.Selfdel.rft
GoogleDetected
AviraHEUR/AGEN.1234650
Antiy-AVLTrojan/Generic.ASBOL.C6F8
MicrosoftTrojan:Win32/Fragtor.EL!MTB
ZoneAlarmHEUR:Trojan.Win32.SelfDel.vho
GDataGen:Variant.Fragtor.111317
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
McAfeeGenericRXNV-VM!C168B1ABFF51
MAXmalware (ai score=84)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.3582201929
RisingStealer.Agent!1.DE3E (CLASSIC)
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.bff517
PandaTrj/Genetic.gen

How to remove Fragtor.111317?

Fragtor.111317 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment