Malware

Fragtor.167136 removal tips

Malware Removal

The Fragtor.167136 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.167136 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.167136?


File Info:

name: 4318B45D82B24229AB28.mlw
path: /opt/CAPEv2/storage/binaries/bf061d5ca6baec1972b0bcf13a0e12b99c25df5ff9059c9ee9695364941ff8b0
crc32: 60FB963C
md5: 4318b45d82b24229ab2888e351a1655c
sha1: eeadd75f0a70c498055a0c291058e87f5a2dbb69
sha256: bf061d5ca6baec1972b0bcf13a0e12b99c25df5ff9059c9ee9695364941ff8b0
sha512: d7d14e9d45dc73aca79cc0cc2027d6abc2f1831a7fb4e6bb4e05985c2bf99c8ac9991f922fadbd65a040b0c6ed9108bf00167210766a127d67cfa4778bb4ba5a
ssdeep: 384:NWvr5+Ux9Kh09RXjXz7XjCWwqK8Wzz8WW5bIwHKWK3VRHY0SvAXbAit3zQXR:EvrTbB9xjXvKBBW5byYboX0Ko
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F0C26D8FB6804870E9D006701572BA7586FF77303EF6D5228B1BEB1619A64A4E70D6CF
sha3_384: 533328b89ede648d3efde359c7d76e4cfb96f50e9f7beb93883d3be61bb3155ed9c099f8d0ec70ac5f7ed89c71c9e7ef
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.167136 also known as:

LionicTrojan.Win32.SelfDel.4!c
MicroWorld-eScanGen:Variant.Fragtor.167136
ClamAVWin.Malware.Fugrafa-9950512-0
FireEyeGeneric.mg.4318b45d82b24229
CAT-QuickHealTrojan.Stealer.S28360516
ALYacGen:Variant.Fragtor.167136
MalwarebytesMalware.AI.3910449943
ZillyaTrojan.SelfDel.Win32.65008
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 005937271 )
AlibabaTrojanPSW:Win32/Fragtor.657d6fa1
K7GWPassword-Stealer ( 005937271 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Fragtor.D28CE0
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.SelfDel.pef
BitDefenderGen:Variant.Fragtor.167136
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
SUPERAntiSpywareTrojan.Agent/Gen-Stealer
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
TACHYONTrojan/W32.Fugrafa.26112
SophosTroj/PWS-CMJ
F-SecureHeuristic.HEUR/AGEN.1318539
DrWebTrojan.MulDrop20.10627
VIPREGen:Variant.Fragtor.167136
TrendMicroTROJ_GEN.R002C0DLT22
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
EmsisoftGen:Variant.Fragtor.167136 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1318539
Antiy-AVLGrayWare/Win32.SelfDef.a
MicrosoftTrojan:Win32/Fragtor.EL!MTB
ZoneAlarmHEUR:Trojan.Win32.SelfDel.pef
GDataGen:Variant.Fragtor.167136
GoogleDetected
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
McAfeeGenericRXNV-VM!4318B45D82B2
MAXmalware (ai score=83)
VBA32BScope.Trojan.Occamy
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLT22
RisingStealer.Agent!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.74774368.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Fragtor.167136?

Fragtor.167136 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment