Malware

Should I remove “Fragtor.28313 (B)”?

Malware Removal

The Fragtor.28313 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.28313 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.28313 (B)?


File Info:

name: 073DB2915413C19000B5.mlw
path: /opt/CAPEv2/storage/binaries/41d2b3139d67e06b4bfa316116e1b0c5617583fa46afaed3fe9434b148fde810
crc32: 61AF2443
md5: 073db2915413c19000b5a93ff949a893
sha1: ec1fc595a5b97b667dc7e2edc56f6b09767951d0
sha256: 41d2b3139d67e06b4bfa316116e1b0c5617583fa46afaed3fe9434b148fde810
sha512: b92652e119795635837a7fb33251ed7989f57d6844b18302e26af27b933a297366034822406587ccd735bd1dd7d5f69cdc28e30a3dab5acead5c131395f53420
ssdeep: 12288:1uLALMWqOGK7EKVKYM2DXogCSz+Z7nFgut+UIk2kTCU/SYEy/SJl+22:Novw1VzXXJCIk2kOsOy/SuN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14E0523F31C8AC72DF27B4EF600D9AC861955E941127136FFB8B1614E0CA915F70AA3DA
sha3_384: 208db1c583f20663f0c8879987b49182a54ebf299e2fbda91796ba8b471db4c844eaf597a8409d066ab7a0b36f82d852
ep_bytes: bf00000000524629f35921f34ebe9bc1
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.28313 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.28313
ALYacGen:Variant.Fragtor.28313
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 005762bf1 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.28313
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.28313
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGen:Variant.Fragtor.28313
EmsisoftGen:Variant.Fragtor.28313 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.28313
JiangminTrojan.Copak.odb
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C688
ArcabitTrojan.Fragtor.D6E99
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4302695
McAfeeGenericRXAA-FA!073DB2915413
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34294.XmW@aGaFGsl
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.5a5b97
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.28313 (B)?

Fragtor.28313 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment