Malware

Fragtor.32003 removal guide

Malware Removal

The Fragtor.32003 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.32003 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.32003?


File Info:

name: 768D66F4E352845EE48E.mlw
path: /opt/CAPEv2/storage/binaries/e1e90e7c743309b0b60f9ee5c34a309eb674b41ab1b4cee47c0fe6da1fa7e663
crc32: 010CB626
md5: 768d66f4e352845ee48eb253c24268f8
sha1: bf625e847c9755dc8f859a151951dd4a28b5dd2b
sha256: e1e90e7c743309b0b60f9ee5c34a309eb674b41ab1b4cee47c0fe6da1fa7e663
sha512: b00fdb2e31d04722e71b40951912915528c7d31093aab95d1b526b17021e046c26c75ecf9bb9d00da07c2d8be022e4948a785b8881c1a9d094013896b3648211
ssdeep: 12288:J9gHjH10aQErIeZtqWdlnfJ9ErvgbLko8gJ7yh6avjfeJ6g5CfwGDt51D:qH10aQEdbbcgbQo8gJmE2KlGj1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AE05336D66D509F8F1FB513680988CE25F33FEDBAD192A5D85F63172A012EB301ABC05
sha3_384: f197ef1ea0bbecfcc7353940a0bf8c0ca0088e9ba56ba56430818a33621f0faf9822cd73ee004edc6b837102a40e257e
ep_bytes: 83ec04c70424000000005b5281ee1f02
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.32003 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.32003
FireEyeGen:Variant.Fragtor.32003
ALYacGen:Variant.Fragtor.32003
CylanceUnsafe
ZillyaTrojan.Copak.Win32.139655
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aWRhLbo
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
Paloaltogeneric.ml
ClamAVWin.Trojan.Coinminerx-9838975-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Fragtor.32003
NANO-AntivirusRiskware.Win32.BitCoinMiner.ijhefb
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
EmsisoftGen:Variant.Fragtor.32003 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosML/PE-A + Mal/HckPk-A
APEXMalicious
JiangminRiskTool.BitCoinMiner.vew
AviraHEUR/AGEN.1140994
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASBOL.C688
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.32003
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R364132
McAfeeGenericRXAA-AA!768D66F4E352
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
IkarusTrojan.Win32.Injector
RisingTrojan.Injector!1.C865 (CLOUD)
YandexTrojan.Kryptik!23eYxPZqJ3k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74654884.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.47c975
PandaTrj/Genetic.gen

How to remove Fragtor.32003?

Fragtor.32003 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment