Malware

Fragtor.29936 (B) (file analysis)

Malware Removal

The Fragtor.29936 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.29936 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

Related domains:

wpad.local-net

How to determine Fragtor.29936 (B)?


File Info:

name: 8F2855FC51BAC4E30E85.mlw
path: /opt/CAPEv2/storage/binaries/ffd02a85e30c1cb440c3f27ca9ffa23ae47cd6026aef08a91acee748ed1cbcaa
crc32: F6409E32
md5: 8f2855fc51bac4e30e857bb8e21993b7
sha1: 833caf8422640ab361c0d71e787eb03f074a1bd6
sha256: ffd02a85e30c1cb440c3f27ca9ffa23ae47cd6026aef08a91acee748ed1cbcaa
sha512: d5ec32531d1ac5cfdd595af37c4ec0c683f49afc9738fa0485d8748efd5b22c0ce0cec3cc7507bdb963786927942b1867ed8563d4c7ab974169774133d07c345
ssdeep: 98304:0VuQxsaIqJZ0IPvxXUi3DsGBZA/RH/+igan2A5b:0VTxFIqDnNlzDW/+i32e
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T191E53333B5169377DB2521B248B1EFF428910F6C66B3A351BDD7EC1D928712A8ACCB11
sha3_384: 7c9eb2203f707df5a9288c5f78529c827dc4ce3509703ee1b889e49f495bacb424ef7146d49740f01c655999c1bc325d
ep_bytes: 68000000008b042483c40457ba3b44ac
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.29936 (B) also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.29936
FireEyeGeneric.mg.8f2855fc51bac4e3
ALYacGen:Variant.Fragtor.29936
CylanceUnsafe
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.422640
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Fragtor.29936
AvastWin32:CoinminerX-gen [Trj]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
EmsisoftGen:Variant.Fragtor.29936 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.29936
JiangminTrojan.Generic.hdhfl
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C689
ArcabitTrojan.Fragtor.D74F0
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
McAfeeGenericRXAA-FA!8F2855FC51BA
MAXmalware (ai score=89)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
TencentTrojan.Win32.Coinminer.yi
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34294.epZ@aW3z7Tn
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.29936 (B)?

Fragtor.29936 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment