Malware

Fragtor.328786 malicious file

Malware Removal

The Fragtor.328786 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.328786 virus can do?

  • A file was accessed within the Public folder.
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Conti malware family
  • Creates a known ContiV2 ransomware decryption instruction / key file.
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.328786?


File Info:

name: 21F39F3233C28C6223FE.mlw
path: /opt/CAPEv2/storage/binaries/174ada6f6ab5b456affb3a05a4549d18d1de9bc0507e0e398f2e2609bba93fd0
crc32: 04D420F5
md5: 21f39f3233c28c6223fe2ad434986f9a
sha1: dc7ac7cecaad626c66597c409cd0c55d439e69db
sha256: 174ada6f6ab5b456affb3a05a4549d18d1de9bc0507e0e398f2e2609bba93fd0
sha512: 132e691782ffd743c9052b329958582fccec9fad016e8042b60047ba36bd01d042303ae4402fa7f45de75350d2ac1c252cafd944777c73da2a20d93cb87ca28d
ssdeep: 3072:/mMQ29VE5LC1PXfb/cfq+Ntct/sU7XNAxbkM5prN0fdpBSjyrI4CBSSxqaDoq1Ch:/mMQLEAqXmF5JGfEjKmBbZ86TS8XWkG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D6246B50B3C58272F1B6183419F9AAB2282DBD70176FC8BBA7D04A291E705D16633F77
sha3_384: 522332c37bbcf842b78e89727a1a9c9cefb33af7565b19191cb7f44f56856df525a594484e6fed2a2ec753f8e9ef042e
ep_bytes: e8f7020000e98efeffff558bec56ff75
timestamp: 2023-09-22 07:47:53

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
FileVersion: 10.0.1941.1
InternalName: svchost.exe
LegalCopyright: @Microsoft Corporation Copyright (C) 1996
OriginalFilename: svchost.exe
ProductName: @Microsoft @Windows Operating System
ProductVersion: 10.0.1941.1
Translation: 0x0409 0x04b0

Fragtor.328786 also known as:

BkavW32.AIDetectMalware
CAT-QuickHealRansom.Conticrypt.S30550132
ALYacGen:Variant.Fragtor.328786
Cylanceunsafe
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZexaF.36722.ny0@aOl7OAbi
SymantecML.Attribute.HighConfidence
ElasticWindows.Ransomware.Conti
ESET-NOD32a variant of Win32/Filecoder.OCA
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Fragtor.328786
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Fragtor.328786
AvastWin32:Conti-B [Ransom]
EmsisoftGen:Variant.Fragtor.328786 (B)
VIPREGen:Variant.Fragtor.328786
TrendMicroRansom.Win32.CONTI.SM.hp
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.21f39f3233c28c62
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
MicrosoftRansom:Win32/Conti.AD!MTB
ArcabitTrojan.Fragtor.D50452
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Fragtor.328786
GoogleDetected
MAXmalware (ai score=89)
VBA32BScope.Trojan.Mansabo
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.CONTI.SM.hp
RisingRansom.Conti!1.D637 (CLASSIC)
IkarusTrojan-Ransom.Conti
AVGWin32:Conti-B [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.328786?

Fragtor.328786 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment