Malware

What is “Fragtor.114196”?

Malware Removal

The Fragtor.114196 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.114196 virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Fragtor.114196?


File Info:

name: A0827E4A7E52C4620B1E.mlw
path: /opt/CAPEv2/storage/binaries/e1e51a2c5dc2171d25078ec368bf2b8cb34b77be55596550272699e27d2ab1bc
crc32: 06A3CD08
md5: a0827e4a7e52c4620b1ed0de24fc298b
sha1: a20716626fa1aae8d5bc7e83b538339772e5c5fa
sha256: e1e51a2c5dc2171d25078ec368bf2b8cb34b77be55596550272699e27d2ab1bc
sha512: 8ad6edcdaec0f59de90d7a73a350e7c03abf0105af4e79cde6da803a5470892b1c4c6980a0979cab2b80e52ff6d92564978901114d1853063ce027c8e98f9f64
ssdeep: 768:RpKies/gGeMHd8ngN047BNATR6Nx3Gzh3RcUEXeQxDvsq:RTR/beM98ngN0wBNAT82zV+gyR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137333943BE6144B3C692827875E52736CFFD64386669F482EB2396837CB40F4E93D606
sha3_384: e4f14c5c53a4a9a1a4eb6497ed8ca1ea0654bb8b07397ee8768972a7313f571f9c6295d37c6bb6e147ebfdcf74857371
ep_bytes: 81ec04010000535556576a015b5368a8
timestamp: 2012-12-27 11:39:54

Version Info:

0: [No Data]

Fragtor.114196 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Fragtor.114196
SkyhighBehavesLike.Win32.Generic.qm
McAfeeArtemis!A0827E4A7E52
ZillyaTrojan.OnLineGames.Win32.137510
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanPSW:Win32/OnLineGames.e7c0a404
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.26fa1a
BitDefenderThetaGen:NN.ZexaCO.36744.dmW@a4kS4Ghb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.OnLineGames.QCU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.OnLineGames2.pik
BitDefenderGen:Variant.Fragtor.114196
NANO-AntivirusVirus.Win32.Patched.buryiv
AvastWin32:OnLineGames-GNB [Trj]
TencentTrojan.Win32.OnlineGames.daq
EmsisoftGen:Variant.Fragtor.114196 (B)
BaiduWin32.Trojan-PSW.OLGames.bp
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.PWS.Wsgame.37378
VIPREGen:Variant.Fragtor.114196
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a0827e4a7e52c462
SophosMal/Behav-010
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.114196
JiangminTrojan/PSW.OnLineGames.cpov
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Fragtor.D1BE14
ZoneAlarmTrojan-GameThief.Win32.OnLineGames2.pik
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Zuten.C.gen!Eldorado
AhnLab-V3Dropper/Win32.OnlineGameHack.R37286
Acronissuspicious
VBA32TrojanPSW.OnLineGames.a
ALYacGen:Variant.Fragtor.114196
TACHYONTrojan-PWS/W32.WebGame.52736.CK
Cylanceunsafe
PandaTrj/Genetic.gen
RisingStealer.OnlineGames!1.64BB (CLASSIC)
YandexTrojan.GenAsa!3a9cosSeYoQ
IkarusTrojan-PWS.Win32.Zakahic
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Onlinegames.PYY!tr
AVGWin32:OnLineGames-GNB [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.114196?

Fragtor.114196 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment