Malware

Fragtor.28187 removal tips

Malware Removal

The Fragtor.28187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.28187 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Hungarian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Fragtor.28187?


File Info:

crc32: CDD317B2
md5: d6089eb2fed51a598931406cea4dff1e
name: D6089EB2FED51A598931406CEA4DFF1E.mlw
sha1: e4de9c53dea38d568bf2a6ea96711ac8389ca1d5
sha256: 6adc8d4b4b2bd38d13e1f41511154a396eee1ef8232e456000cc18936feb9d41
sha512: 9bec4d2f029e7cd7369a445b36e25c8347891eec81ae9e98d595d525ecaf650b5e42db6837b2ee6312026eebd66d51e9dc7ca1786fbf72e1a037f2581533264e
ssdeep: 6144:E5GL5xP2MkgExwS4CXrqJL6wmbOOhxxdeTr/ekI:Eg9J2MXExx4CXcL67Hzxd6L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sajbmianozu.iya
ProductVersion: 2.4.59.52
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0127 0x007a

Fragtor.28187 also known as:

K7AntiVirusTrojan ( 005885611 )
LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.15690
CynetMalicious (score: 100)
ALYacGen:Variant.Fragtor.28187
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Mokes.d0310bf4
K7GWTrojan ( 005885611 )
Cybereasonmalicious.3dea38
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMSH
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Mokes.gen
BitDefenderGen:Variant.Fragtor.28187
MicroWorld-eScanGen:Variant.Fragtor.28187
TencentWin32.Backdoor.Mokes.Wopk
Ad-AwareGen:Variant.Fragtor.28187
SophosMal/Generic-S
ComodoMalware@#23aooy5nt1hhi
BitDefenderThetaGen:NN.ZexaF.34170.qq0@aiJh0leO
TrendMicroTROJ_FRS.0NA103J321
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dh
FireEyeGeneric.mg.d6089eb2fed51a59
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Infostealer.Raccoon
Antiy-AVLTrojan/Generic.ASMalwS.34A98A7
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RMA!MTB
ArcabitTrojan.Fragtor.D6E1B
GDataGen:Variant.Fragtor.28187
AhnLab-V3Infostealer/Win.SmokeLoader.R443617
Acronissuspicious
McAfeePacked-GDT!D6089EB2FED5
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103J321
RisingTrojan.Generic@ML.91 (RDMK:mrO6pXyUvxquU53QYcDT4g)
IkarusTrojan.Crypt
FortinetW32/Agent.GDT!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Fragtor.28187?

Fragtor.28187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment