Malware

Fragtor.28447 removal

Malware Removal

The Fragtor.28447 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.28447 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.28447?


File Info:

name: B0ABDA56542E5C1273B4.mlw
path: /opt/CAPEv2/storage/binaries/a206218637a814ef628352ab804cf16017e134e179801a95b863029c927af900
crc32: CD054B12
md5: b0abda56542e5c1273b44004b37bc448
sha1: 0d9c764c7616479f8b0d15f3205adaa8edffe9aa
sha256: a206218637a814ef628352ab804cf16017e134e179801a95b863029c927af900
sha512: 580d78629ab5f88c18280ad54a8b43e88cab623df161ac1dd999e3d1cd534d0e1599e492794be32253ac21a624e5b3a7b8c549675717eb683e04a05c2f464ced
ssdeep: 24576:5tV8T/hF74CpV3rkWpwjWzHxyqPUGnNL:7VxK3rxpDyWD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C60523DA9EF84234D5B8803A1B0CB2A75744168F8B3D4E06ECD56C9B45F79A5081BF3D
sha3_384: 3d6fa90a0f2d4335277691ebdab2cd4e8f0088dde0729a2672fb8fdfe82a1adc59ddf58a20c10f09e743ec73b54e990f
ep_bytes: be000000005709db83ec04891c245b09
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.28447 also known as:

DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Fragtor.28447
FireEyeGen:Variant.Fragtor.28447
ALYacGen:Variant.Fragtor.28447
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Kryptik.HITO
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aWIJJyn
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
TrendMicro-HouseCallTROJ_GEN.R03FC0DJ621
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.28447
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosMal/Generic-S + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
TrendMicroTROJ_GEN.R03FC0DJ621
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Fragtor.28447 (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitCoinMiner.xbm
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASBOL.C687
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.28447
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R364189
McAfeeGenericRXAA-FA!B0ABDA56542E
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.74654884.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.28447?

Fragtor.28447 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment