Malware

Fragtor.19069 (B) malicious file

Malware Removal

The Fragtor.19069 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.19069 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.19069 (B)?


File Info:

name: D038255FB315ADFCFA9D.mlw
path: /opt/CAPEv2/storage/binaries/4c2c6364aebc9bbd8185718f745e2d71b024846be3ede0e3bcfb73fb52d30076
crc32: AFEA5062
md5: d038255fb315adfcfa9dc53da54c0ca5
sha1: 8c5c8408ce01ab4aba8f8612e6cbb3d748e1385c
sha256: 4c2c6364aebc9bbd8185718f745e2d71b024846be3ede0e3bcfb73fb52d30076
sha512: a71c214997487839b2d5375c70c372c3a2066273af6830b5d745fb239a3b773fcef6c69998443e7d26f924c9d750687b467a3eeacc48d7565ceeb64eb9683ecb
ssdeep: 12288:ZiqDzlGipCjz4Y/DKuETZFJ70OoEJszuKalAYD5pCm/Y09b6XYGeQ1TJQkJiTb3a:ZlDsQIFLnETJ0d/YOml9OXYVa63GAt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1640523DEDE4205B2E045E6FEB42029FA363C73D9AAEA99178CD00A0F14761DE5E20D57
sha3_384: 9c528152b93ca513ab14db30495506ed3c0ab4a65f217c0188350da36f84c1ce526b9f39840ba6fc3326f76946305ac3
ep_bytes: 68000000005a5381ef7da8a43909c05e
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.19069 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Fragtor.19069
FireEyeGen:Variant.Fragtor.19069
ALYacGen:Variant.Fragtor.19069
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00576fb91 )
K7GWTrojan ( 005762bf1 )
BitDefenderThetaGen:NN.ZexaF.34212.XmW@a8pJ0Lj
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.19069
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.19069
EmsisoftGen:Variant.Fragtor.19069 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Mal/HckPk-A
IkarusTrojan.Win32.Injector
GDataGen:Variant.Fragtor.19069
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68F
ArcabitTrojan.Fragtor.D4A7D
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4302695
McAfeeGenericRXAA-FA!D038255FB315
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
APEXMalicious
RisingMalware.Heuristic!ET#90% (RDMK:cmRtazqbBvvVC6rnUWhefFNNRymX)
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.19069 (B)?

Fragtor.19069 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment