Malware

About “Fragtor.12980” infection

Malware Removal

The Fragtor.12980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.12980 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Fragtor.12980?


File Info:

crc32: C86763AD
md5: ebf15c6db0a62d32a2a15a8f13e1c88f
name: EBF15C6DB0A62D32A2A15A8F13E1C88F.mlw
sha1: 254f6d8896b865d6b35413c838c6a1779267f044
sha256: db148eccfdeedddeca41eb2ac092db09e6c568b714e5f2d9b2560bf5b2551952
sha512: fc687c040053d40115ee17b88e781bb1fb943c9d46ee276eb55e72b4987c7ae675457c3149ed97469a3a4336cfa97990b24087c76e26e1ab120754f15d9f0b0b
ssdeep: 3072:o7zD5RnUK62wDyiMqM2aRXQ95rRDYHlZeAPph7pbpBsI5/DuT61m:o7vnUK62wpDEQnilwE5sI5/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.axi
ProductVersion: 7.19.28.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0181 0x022e

Fragtor.12980 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Fragtor.12980
K7GWHacktool ( 700007861 )
Cybereasonmalicious.896b86
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.Win32.Mokes.gen
MicroWorld-eScanGen:Variant.Fragtor.12980
Ad-AwareGen:Variant.Fragtor.12980
BitDefenderThetaGen:NN.ZexaF.34110.nq0@aGwi8ddG
TrendMicroMal_HPGen-50
FireEyeGeneric.mg.ebf15c6db0a62d32
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fragtor.12980
Acronissuspicious
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.94%
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.12980?

Fragtor.12980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment