Malware

How to remove “Fragtor.81167”?

Malware Removal

The Fragtor.81167 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.81167 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a copy of itself

How to determine Fragtor.81167?


File Info:

name: 2FF64525E896C60DB522.mlw
path: /opt/CAPEv2/storage/binaries/10a5a8b579ecb112f3b2f62d46fa1aac1507db71110e17f360b143c179453678
crc32: 7BC4EDBB
md5: 2ff64525e896c60db5223f4278c72306
sha1: b1b1849b823b7dd7c3a71b532af646f21e7bb41d
sha256: 10a5a8b579ecb112f3b2f62d46fa1aac1507db71110e17f360b143c179453678
sha512: 2e0893590b0df5b1a5bf1bf4cfd4e0f6863b641c09f16c0560538518f0549522e5512fe5d5496971844aef285cdeebd54be9f45038006701dab0d41a1548e4ea
ssdeep: 196608:7Mrab9DPnG+S43xLJYswi+ABK1tMMlvPB3ZtWpFf8pXcB27f7e3VwjBQozv:7MolPG+hxbpmlZugXcB27f3Qor
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3D6330E07B5B3D8EC96E0736D43A5E22C933FD915D221FA8E8DB5A10335D988A7DB05
sha3_384: 32d61789518a72dd3d14feb62e14341ab92052b582af8743de8723f08a55cdb206a0da42c768e5f77ba15ee305bbec5e
ep_bytes: 60be00d0d8008dbe004067ff5789e58d
timestamp: 2022-04-18 09:28:17

Version Info:

FileVersion: 1.0.0.0
FileDescription: .
ProductName: .
ProductVersion: 1.0.0.0
CompanyName: .
LegalCopyright: .
Comments: .
Translation: 0x0804 0x04b0

Fragtor.81167 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Fragtor.81167
ALYacGen:Variant.Fragtor.81167
CylanceUnsafe
SangforPUP.Win32.Caypnamer.A!ml
Cybereasonmalicious.b823b7
ArcabitTrojan.Fragtor.D13D0F
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
KasperskyTrojan.Win32.SelfDel.hyyz
BitDefenderGen:Variant.Fragtor.81167
AvastFileRepMalware [Misc]
Ad-AwareGen:Variant.Fragtor.81167
EmsisoftGen:Variant.Fragtor.81167 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Flyagent.rc
FireEyeGeneric.mg.2ff64525e896c60d
SophosGeneric ML PUA (PUA)
JiangminBackdoor/Blackhole.pjm
AviraHEUR/AGEN.1200821
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataWin32.Trojan.PSE.15PTMPD
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.C5105624
Acronissuspicious
McAfeeArtemis!2FF64525E896
MAXmalware (ai score=83)
VBA32MalwareScope.Trojan-PSW.Game.16
TrendMicro-HouseCallTROJ_GEN.R002H0CE122
RisingTrojan.SelfDel!8.275 (CLOUD)
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34638.@pNfaeGXuNnH
AVGFileRepMalware [Misc]

How to remove Fragtor.81167?

Fragtor.81167 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment