Malware

Fragtor.23498 (B) removal instruction

Malware Removal

The Fragtor.23498 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.23498 (B) virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.23498 (B)?


File Info:

name: D75933AA88FDB23AAA99.mlw
path: /opt/CAPEv2/storage/binaries/8a6dbf53af2ce6db36e16d469882ec09956603f5a71459159dab1182713d96d0
crc32: F3FEB366
md5: d75933aa88fdb23aaa998fc711ebd090
sha1: 39874e22bff3cd7b9688051b9caf9f45fc868974
sha256: 8a6dbf53af2ce6db36e16d469882ec09956603f5a71459159dab1182713d96d0
sha512: e79b404acc3f4f11b89908bd1be71ebb1f6b495614a1ef0db162d044a78bfc361658dd5e155392b6f6cd39abaebfa11a9dbbdf379b708494d69eda1b2afe4cc9
ssdeep: 98304:1vISGb1Ld9w/FmF3CzA70sLfkK9s8TU2moI/1ul6s0Z6BqXdiwhpHZSb0E/Ghu4Y:1PuLdYFmF3CzA70sLfkK9s8TU2bI/1ug
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B36AFD6934D156ED192D0FEF31FA79255F5AE3A261EC383F380BA2318912D2B664D03
sha3_384: dc23bda04975e727c5326eea9dffcc1c0906e5016f26e835163038f9f01b6e3b9a6c18faeb9c1a705e6883af12116232
ep_bytes: e887040000e980feffff558bec5156ff
timestamp: 2018-08-16 04:40:07

Version Info:

0: [No Data]

Fragtor.23498 (B) also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fragtor.23498
ALYacGen:Variant.Fragtor.23498
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Fragtor.23498
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fragtor.23498
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Generic.e
EmsisoftGen:Variant.Fragtor.23498 (B)
F-SecureHeuristic.HEUR/AGEN.1319114
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
FireEyeGeneric.mg.d75933aa88fdb23a
SophosSoftcnapp (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.23498
GoogleDetected
AviraHEUR/AGEN.1319114
MAXmalware (ai score=85)
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ArcabitTrojan.Fragtor.D5BCA
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
McAfeeSoftcnapp
Cylanceunsafe
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.BBEC (CLASSIC)
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Softcnapp.BC
BitDefenderThetaGen:NN.ZexaF.36348.@BW@aqf8FFaj
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a88fdb
DeepInstinctMALICIOUS

How to remove Fragtor.23498 (B)?

Fragtor.23498 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment