Malware

Fragtor.17304 removal tips

Malware Removal

The Fragtor.17304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.17304 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
api.ipify.org
a.tomx.xyz

How to determine Fragtor.17304?


File Info:

crc32: 89BDF4FE
md5: fc1018b13ca793a1ef46fc19a83fb125
name: FC1018B13CA793A1EF46FC19A83FB125.mlw
sha1: de24736baabfdae0f0d0cb2e256c66fbb0202bdc
sha256: 3608623142129c9ecd0a7bd16fc5737bbc964e08be41b7e81a33cd806657e64c
sha512: fa1bc7a6f96db15ef15de86f40a4ffc84a10f0de3837d682d48d5c39afbfb778290c38e45e63349fd3513e05d85b4dccbeab75cb0b8389b462b685c1ea139c31
ssdeep: 6144:J/YdnpTLSv7zR/JZdYUnOy+o8kTzauS9mNafyDAtzCCmqpP:0npqTzZJUWO5o8/N9mNa6D0PPpP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Fragtor.17304 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00575b651 )
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Bunitu-9819420-0
ALYacGen:Variant.Fragtor.17304
MalwarebytesTrojan.MalPack.GS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/StopCrypt.20b46c5d
K7GWTrojan ( 00575b651 )
Cybereasonmalicious.13ca79
CyrenW32/Kryptik.CXK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIMZ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Mokes.vho
BitDefenderGen:Variant.Fragtor.17304
NANO-AntivirusTrojan.Win32.Ficker.iifbnn
MicroWorld-eScanGen:Variant.Fragtor.17304
TencentWin32.Trojan-qqpass.Qqrob.Eddg
Ad-AwareGen:Variant.Fragtor.17304
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34170.vmLfaa@WlrlG
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.fc1018b13ca793a1
EmsisoftGen:Variant.Fragtor.17304 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Ficker.z
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASCommon.1E7
MicrosoftTrojan:Win32/Glupteba.NW!MTB
ZoneAlarmHEUR:Backdoor.Win32.Mokes.vho
GDataGen:Variant.Fragtor.17304
AhnLab-V3Malware/Win32.RL_Generic.R362253
Acronissuspicious
McAfeeArtemis!FC1018B13CA7
MAXmalware (ai score=88)
VBA32BScope.Trojan.Caynamer
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
YandexTrojan.PWS.Ficker!KDi08t0Vsdc
IkarusTrojan.MalPack
FortinetW32/Kryptik.HIFA!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Fragtor.17304?

Fragtor.17304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment