Malware

Fragtor.115980 malicious file

Malware Removal

The Fragtor.115980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.115980 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.115980?


File Info:

name: FC994A33752CF7E6191B.mlw
path: /opt/CAPEv2/storage/binaries/686fa8195e584a07db7c74ccda1564cc97046211865f6bda1576a0734b392a00
crc32: 05347A3D
md5: fc994a33752cf7e6191b75a263bfc597
sha1: cdaeb1470c898a99fa9b0309dfaba8cdf401ee28
sha256: 686fa8195e584a07db7c74ccda1564cc97046211865f6bda1576a0734b392a00
sha512: 8bdf684352f9c50353bd899f4289ab8c96cb73d15cc2d54106ad9816026457230a1618b62b7da4fa4fbf7268138324ad40c62adbceecd581bdb824e819588708
ssdeep: 384:IWizGIj2Ux9ML2Oqw09RXjXz7XjCWwqK8Wzz8WW5bIwHXzZuKJesxi6gqM2:3iCI5bPX9xjXvKBBW5bBM6gw
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C6C29F47B7C14C33DFD15A72B8B2CAF881FF78601916A1A21F31E2251DA64E0FB161C9
sha3_384: 51b141c22e20821047c394107e2b3ab79f6e182f2256c90cfdafeb70f863856acedc681bc7251b5449bc0351c8f4cce6
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.115980 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.115980
FireEyeGeneric.mg.fc994a33752cf7e6
ALYacGen:Variant.Fragtor.115980
MalwarebytesMalware.AI.2397151589
VIPREGen:Variant.Fragtor.115980
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.3752cf
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.115980
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.115980
TACHYONTrojan/W32.Fugrafa.26112
EmsisoftGen:Variant.Fragtor.115980 (B)
F-SecureHeuristic.HEUR/AGEN.1234650
DrWebTrojan.MulDrop20.10627
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SophosTroj/PWS-CMJ
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
Antiy-AVLGrayWare/Win32.SelfDef.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.SelfDel.vho
GDataGen:Variant.Fragtor.115980
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
McAfeeGenericRXNV-VM!FC994A33752C
MAXmalware (ai score=87)
VBA32BScope.Trojan.Occamy
RisingStealer.Agent!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.5437263.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fragtor.115980?

Fragtor.115980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment