Malware

Fragtor.11542 removal guide

Malware Removal

The Fragtor.11542 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.11542 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

4kcontent.xyz
iplogger.org
api.ip.sb
freegeoip.app
youtube4kdowloader.club

How to determine Fragtor.11542?


File Info:

crc32: 2F136D06
md5: ba96158061a6539ba5e2b85e69609001
name: BA96158061A6539BA5E2B85E69609001.mlw
sha1: 576ee820a00f3fee2b294618f15f8dbd946e9b4e
sha256: c5577bb5b44d4876cc6e6a0260dd0f0956bd70b945793df747fa2fa4e51ea33e
sha512: 491bd973868f4e28b4643f9204f54f1d42efe3248453fa5788e11169f6b7f4c04b7596c437578521e7e2e3c06b275d02a85329d5ac327bebd5af35aebb9b4f6e
ssdeep: 6144:yQMG0zUBvM7qcQRqAnHsBs7snq8bEcxb:yQwzyvM7Sk+72lEcF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloke.awi
ProductVersion: 7.59.22.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Fragtor.11542 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056f9be1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFI
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Fragtor-9888193-0
KasperskyHEUR:Trojan-PSW.Win32.Tepfer.gen
BitDefenderGen:Variant.Fragtor.11542
MicroWorld-eScanGen:Variant.Fragtor.11542
Ad-AwareGen:Variant.Fragtor.11542
SophosMal/Generic-R + Troj/Krypt-W
BitDefenderThetaGen:NN.ZexaF.34104.uq0@aeDibNeG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.ba96158061a6539b
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_91%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan-Spy.BeamLoader.4D10SV
AhnLab-V3CoinMiner/Win.Glupteba.R438695
Acronissuspicious
McAfeePacked-GDT!BA96158061A6
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EWJ!tr
AVGFileRepMalware

How to remove Fragtor.11542?

Fragtor.11542 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment