Malware

Should I remove “Fragtor.141766”?

Malware Removal

The Fragtor.141766 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.141766 virus can do?

  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Fragtor.141766?


File Info:

name: 488E8D809F7A6729A203.mlw
path: /opt/CAPEv2/storage/binaries/b8713f152c8de9922e598c0dbb37f1062def9ad5994cad5152a3b188d983f1d8
crc32: BD070A54
md5: 488e8d809f7a6729a20364befc44dc84
sha1: deb9af3027709c65bc8e5941bf5dfb4f3e86fe66
sha256: b8713f152c8de9922e598c0dbb37f1062def9ad5994cad5152a3b188d983f1d8
sha512: 6f5fc48b2dccd005b8c3d43b9f68502debf29d36cf6488ca476062eabb01c9c4d3aaf7442899b51e26ddef29e45eb5c87fecb8f6fb70ebe81a07547cb04fc99f
ssdeep: 6144:bzx2VdBNhAjDdU3ynzrTbmPG0NCyA5LnJ6rqWN:bNcdHCyCzrvmPG0EtnyDN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF24125E2A609C13E932177BD4F3E7B83BD89E505C4E5B831400BF6F2AFD89B1925096
sha3_384: b0d01ab7e50812ec589eac648919b4ee93c47cd37f9375b366c14b017421958e8e4878515b213f04100f4ffb94dbbf05
ep_bytes: 60be004045008dbe00d0faffc787a080
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Goоgle Inc.
FileDescription: Desktop Search Engine
FileVersion: 8.5.0.1
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0409 0x04e4

Fragtor.141766 also known as:

CynetMalicious (score: 100)
VIPREGen:Variant.Fragtor.141766
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Fragtor.141766
Cybereasonmalicious.09f7a6
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Spy.Delf.QTM
APEXMalicious
MicroWorld-eScanGen:Variant.Fragtor.141766
AvastWin32:Adware-gen [Adw]
EmsisoftGen:Variant.Fragtor.141766 (B)
Trapminemalicious.moderate.ml.score
FireEyeGen:Variant.Fragtor.141766
SophosMal/DelfSpy-F
IkarusTrojan.Win32.Redcontrole
WebrootW32.Trojan.Gen
GoogleDetected
MAXmalware (ai score=85)
Antiy-AVLTrojan[Spy]/Win32.Delf
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Fragtor.D229C6
GDataGen:Variant.Fragtor.141766
AhnLab-V3Trojan/Win.Generic.R438850
VBA32BScope.Trojan.Agent
ALYacGen:Variant.Fragtor.141766
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:u4qKb3Ihw1CBPDUiEtga1Q)
YandexTrojan.GenAsa!mQ3+XHe10x4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Delf
BitDefenderThetaAI:Packer.44F9DC5015
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Fragtor.141766?

Fragtor.141766 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment