Malware

Fragtor.31012 removal instruction

Malware Removal

The Fragtor.31012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.31012 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.31012?


File Info:

name: 3DD162A241E86D332428.mlw
path: /opt/CAPEv2/storage/binaries/5b13fd687cd8655aa10d13bb7f6038190834bfecb09592279d6269d75e8cf24b
crc32: 11073066
md5: 3dd162a241e86d3324282cf59403516b
sha1: 1fd6e7f4b1f8d6e90206e62eb2461330b038923f
sha256: 5b13fd687cd8655aa10d13bb7f6038190834bfecb09592279d6269d75e8cf24b
sha512: 57d05c9af1fb6f6a3fbf2df178f8427c098dba55b65c5ebe0f2fd6ee49078f7003a20fa11ca88c00c2ef393b843184b60c9130e6007e216859309d9f33d3fe10
ssdeep: 49152:thAmvCYQCd2pGrc+3rvT8MfMXvTCnOt9/azhDHQeYzGkwRcN6/R0IHvC:fAT02poc+3rTNfGvZ/azhseKjwR0k
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T159B533B676AB7C6EF83E8437889195C252F18C666E0FF8541304AD5214879F22F89FDC
sha3_384: ca5f0a46d17a60b19a43791d725d00b36f2226fe0bc640900a1422402a2bf0280b079f517128c7d696296a283b528e5d
ep_bytes: be000000005109d089d201c05f81e8ae
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.31012 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.31012
FireEyeGen:Variant.Fragtor.31012
ALYacGen:Variant.Fragtor.31012
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3630486
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Fragtor.31012
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.31012
EmsisoftGen:Variant.Fragtor.31012 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Fragtor.31012 (2x)
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASBOL.C68B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Gen.Reputation.C4303220
McAfeeGenericRXAA-FA!3DD162A241E8
MAXmalware (ai score=84)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Kryptik!GE4m4Dy4/oc
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34062.XmW@a8bS7ti
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.31012?

Fragtor.31012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment