Malware

What is “Fragtor.93798”?

Malware Removal

The Fragtor.93798 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.93798 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.93798?


File Info:

name: AFD152E35FE7F1907CCC.mlw
path: /opt/CAPEv2/storage/binaries/d7de57b3deafc8c3bf621e211bc2d816c99eb0eed5dd0ae6cb8af51c341ee3f5
crc32: 15B131B1
md5: afd152e35fe7f1907cccaf423a41c3d3
sha1: 99ec7906c1c20e6d3e5ad39567490df261e6d2b8
sha256: d7de57b3deafc8c3bf621e211bc2d816c99eb0eed5dd0ae6cb8af51c341ee3f5
sha512: 98f79510d907c2a3fad6e6ef1d3909a774d7865cecd07fcd4ec2b86a6a3a4e6d373eb904a3f0092e1201c8a6099876db488dce80099d0661b05bb1f9a1c8104a
ssdeep: 768:iPeMbsT9xjXvKBBW5bk4iNlEKQC0tidKl0xk:i+TDjSBBWbKQC0tidKr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T181C28E2BB9B14461CFB10DF06131D57C8ABFBF300DFDCAA29B63F56209B9050E969685
sha3_384: 525200430289ccb99d13335d01f165d8e4369a724cded17051fdf9405e4a3d475af3183d3b5838b5c418c94c8015a677
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.93798 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.93798
FireEyeGeneric.mg.afd152e35fe7f190
McAfeeGenericRXNV-VM!AFD152E35FE7
CylanceUnsafe
VIPREGen:Variant.Fragtor.93798
K7AntiVirusPassword-Stealer ( 005937271 )
BitDefenderGen:Variant.Fragtor.93798
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.35fe7f
CyrenW32/Agent.ENB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OOO
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
RisingStealer.Agent!1.DE3E (CLASSIC)
Ad-AwareGen:Variant.Fragtor.93798
TACHYONTrojan/W32.Fugrafa.26112
EmsisoftGen:Variant.Fragtor.93798 (B)
DrWebTrojan.MulDrop20.10627
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SophosTroj/PWS-CMJ
APEXMalicious
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
Antiy-AVLTrojan/Generic.ASBOL.C6F8
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fragtor.93798
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Fragtor.93798
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2397151589
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfdel.xb
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Fragtor.93798?

Fragtor.93798 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment