Malware

Fragtor.130301 (file analysis)

Malware Removal

The Fragtor.130301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.130301 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.130301?


File Info:

name: B373735953034D111D4A.mlw
path: /opt/CAPEv2/storage/binaries/47a45eac8e5d0df69c668fb17906c4101b9a2ddb6b96a8f4600abe2b311741f3
crc32: 89BF2D74
md5: b373735953034d111d4a731d44857405
sha1: 4f8a0a157b6c620b2dbb1516fdc51e9f02103ebe
sha256: 47a45eac8e5d0df69c668fb17906c4101b9a2ddb6b96a8f4600abe2b311741f3
sha512: 1f8276de2dc97eb6c4b3c835c63c1681358aefdecce921ba0e2a8b70988976d0265dff3c314c5867a6a9745e0bde348010d2a1631a031b38a426ea48e076abae
ssdeep: 384:Ky7w/jpHowi7zK2DVA1Mhd72ttA8fwd5ASc:KyElH3i722w072LLfI2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139F2C50BD72445A0CA6EC83054F717385B31EC6A9D9A8B7BFF45FE4E14B5210AF2621E
sha3_384: 2f228b80f55b4f24c073e1bcd3a04eb73d606af3548e5d9a10c83296d7eecacfee296ff4a77d1e4dd595aed36cd54e0c
ep_bytes: 558bec6aff68303b400068442b400064
timestamp: 2022-08-12 03:19:48

Version Info:

CompanyName:
FileDescription: DFL Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: DFL
LegalCopyright: 版权所有 (C) 2022
LegalTrademarks:
OriginalFilename: DFL.EXE
ProductName: DFL 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Fragtor.130301 also known as:

Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen18.51495
MicroWorld-eScanGen:Variant.Fragtor.130301
FireEyeGeneric.mg.b373735953034d11
CylanceUnsafe
VIPREGen:Variant.Fragtor.130301
K7AntiVirusRiskware ( 00584baa1 )
AlibabaBackdoor:Win32/Crysan.9e4af4eb
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaCO.34682.cq0@am8Zmpcb
CyrenW32/Agent.FBF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GLD
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Crysan.gen
BitDefenderGen:Variant.Fragtor.130301
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan-Downloader.Oader.Bnhl
Ad-AwareGen:Variant.Fragtor.130301
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Fragtor.130301 (B)
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraTR/Dldr.Agent.gwqui
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.75E4
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Fragtor.130301
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.Small.C5223549
ALYacGen:Variant.Fragtor.130301
MalwarebytesBackdoor.AsyncRAT
RisingTrojan.Generic@AI.100 (RDML:jPqKQZOnoqHOlqG4kIUcow)
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent.GLD!tr.dldr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.57b6c6

How to remove Fragtor.130301?

Fragtor.130301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment