Malware

Fragtor.30500 (B) removal instruction

Malware Removal

The Fragtor.30500 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.30500 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

Related domains:

wpad.local-net

How to determine Fragtor.30500 (B)?


File Info:

name: 98E2FEDDA50CBEDB8511.mlw
path: /opt/CAPEv2/storage/binaries/1497575442520a96eeefd0c9cc04fbc74c4365ecb995742241cd97984dffcb9c
crc32: DA66F3E6
md5: 98e2fedda50cbedb8511cbe889eba26b
sha1: fdbf1071004b4a8bacc567828d6acb4b16aca6d2
sha256: 1497575442520a96eeefd0c9cc04fbc74c4365ecb995742241cd97984dffcb9c
sha512: e064ba9c076137154707fbd7d0a81f1c016f72727b9c64f31236b65335d8beaf4e6c1b7cce8c024af46c3f678e511ca9320176c6f1ee435ff758c4a1c8b112aa
ssdeep: 49152:Vt+9UV3suH8dEI3bxSnKwk+FW7IX2dCm/oXjuLUu33Wajadi6ZqiYC9xBC/Y66LT:7+qZC9SnVB2o43WatiYxYndosbliSS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14BE5333AF828FBFBCF96AE7C22515B0B5434D8DF54C4842717532411926A2EF9CE1A93
sha3_384: 98ce8781351a024b3ad041f8613f62a246eab60de9cb137db13e59021d8ab07acc91d1f3ee76b22da22681403ff43ac0
ep_bytes: b8000000005329ff01c929cf5e68c65b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.30500 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Fragtor.30500
FireEyeGeneric.mg.98e2fedda50cbedb
McAfeeGenericRXAA-FA!98E2FEDDA50C
MalwarebytesTrojan.Crypt.UPX
VIPREPacker.NSAnti.Gen (v)
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.da50cb
BitDefenderThetaGen:NN.ZexaF.34294.epZ@aymeG2f
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
AvastWin32:CoinminerX-gen [Trj]
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Fragtor.30500
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.30500
EmsisoftGen:Variant.Fragtor.30500 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Copak.Win32.160657
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Fragtor.22426
JiangminTrojan.Generic.hbvws
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68E
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R364132
ALYacGen:Variant.Fragtor.30500
MAXmalware (ai score=82)
VBA32Trojan.Packed
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.30500 (B)?

Fragtor.30500 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment