Malware

Fragtor.31231 removal

Malware Removal

The Fragtor.31231 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.31231 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Fragtor.31231?


File Info:

name: 98BDE57BAA9B59D3ECA8.mlw
path: /opt/CAPEv2/storage/binaries/5a6171e865457c5635969d1f695458c9a8d35fe42b5ae0414ceae9aa7b09d471
crc32: 3C784064
md5: 98bde57baa9b59d3eca8ea6f885e1885
sha1: 02247902aa8446aa3f89ec4e8948546547ee67e7
sha256: 5a6171e865457c5635969d1f695458c9a8d35fe42b5ae0414ceae9aa7b09d471
sha512: f6e86ae20239a93f13ff2644cd22367c211ea1a5f23c8f4981027808087ae20c1463110066f0b65fb24c63b0a95bc6789cff9bd043ff735373323bde892c04ca
ssdeep: 98304:fXrDL/pUPdUcACjGAzBHyt7nKlPnoAiA/zsCO4DrjIIJoq3B3oC1YI3d0O9aHg/C:zZod7niA7bDrjXRx3qId0yYVte
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13156233342324186E5F1CC3A562B7EE572F703998B41A87C65EBACC538229E4F356D93
sha3_384: da082cd2c5f7bf8790e2232ef1f5ca32d7e1395860b295ab34abb143eca2e270b2abcdb6a6c2575f927436b375fd571d
ep_bytes: 682d232fbce8c78acfff4ae9200bcfff
timestamp: 2022-02-01 19:56:52

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Fragtor.31231 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.31231
ALYacGen:Variant.Fragtor.31231
CylanceUnsafe
K7AntiVirusTrojan ( 0056e6e91 )
BitDefenderGen:Variant.Fragtor.31231
K7GWTrojan ( 0056e6e91 )
Cybereasonmalicious.2aa844
BitDefenderThetaGen:NN.ZexaF.34182.@B0@aaGzJsgb
CyrenW32/Trojan.GRW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.AO potentially unwanted
KasperskyVHO:Trojan.Win32.Blamon.gen
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpwC1DFL9ItPUf8QeleHyts)
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.98bde57baa9b59d3
EmsisoftGen:Variant.Fragtor.31231 (B)
APEXMalicious
MAXmalware (ai score=84)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Application.PUPStudio.A
CynetMalicious (score: 100)
MalwarebytesPUP.Optional.ChinAd
IkarusTrojan.Win32.Krypt
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll

How to remove Fragtor.31231?

Fragtor.31231 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment