Malware

About “Fragtor.30866” infection

Malware Removal

The Fragtor.30866 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.30866 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.30866?


File Info:

name: AA465E234320C06784FE.mlw
path: /opt/CAPEv2/storage/binaries/6f77e78b311193dac61b62dff2628a51702a1793a19c9546e9a48aef5b452604
crc32: 915535FD
md5: aa465e234320c06784fe70ded58dd0f7
sha1: 9084d9685f3e6f7747fbb8e11b201e2455aacae8
sha256: 6f77e78b311193dac61b62dff2628a51702a1793a19c9546e9a48aef5b452604
sha512: 4439fbc39208bde9682ed579795ff8c778ad87fa48c3910855059424e55760bbb98e0ae37b0a950a76f3a83818fec7623bafd94c920412a7b6ba099239ec0aef
ssdeep: 49152:Wjyxr3FvzEqcEmp70aOOIsExxTl4Izv+C3fAovdYu:oURvzEqFmCfOIVbpPA7u
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T129B53311F3D4EB21CAEE8AF511BA3D1B952DF274567A38C31DD18C98EED15E0E125231
sha3_384: 72334c7766d3a40b19e810420fcbb7d1ecdc412453c33b49617704abb0dad13a6b7509fa6a4e1eddff3c6290a1e5fc3e
ep_bytes: b9000000005201fe09f681eec1c50237
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.30866 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Fragtor.30866
FireEyeGen:Variant.Fragtor.30866
ALYacGen:Variant.Fragtor.30866
MalwarebytesRiskWare.BitCoinMiner.UPX
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.85f3e6
BitDefenderThetaGen:NN.ZexaCO.34062.toZ@aeFnovj
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
AvastWin32:CoinminerX-gen [Trj]
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.30866
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.30866
EmsisoftGen:Variant.Fragtor.30866 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosML/PE-A
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68D
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.30866
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4303581
McAfeeGenericRXAA-FA!AA465E234320
MAXmalware (ai score=84)
VBA32Trojan.Packed
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.30866?

Fragtor.30866 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment