Malware

Fragtor.41311 (B) removal

Malware Removal

The Fragtor.41311 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.41311 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

microsoft-com.mail.protection.outlook.com
quadoil.ru

How to determine Fragtor.41311 (B)?


File Info:

crc32: 44B5776E
md5: b40f5475117331b316e00d9e6e3014f1
name: B40F5475117331B316E00D9E6E3014F1.mlw
sha1: 0150a108ceed7411e8e61cc4a57329e6b42ead58
sha256: 6fbb31568269dbf45de706b5e385506b19fe060bbe756ec992db611bdeba766d
sha512: a0eb1897c4b4e3e71fd4e68486b09c0e5806e63a72423cc2c7e32eb71438fc34c0337a4dbb2ccfce135027f2ce935cf6099c9307372970f8bb74afb7c2c5bd28
ssdeep: 24576:BX2kz8111111111111111111111111111111111111111111111111111111111:BG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 13.54.37.21
Copyright: Copyrighz (C) 2021, fudkat
Translation: 0x0187 0x046a

Fragtor.41311 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.42535
ClamAVWin.Packed.Generic-9908949-0
McAfeePacked-GEE!B40F54751173
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8ceed7
CyrenW32/Kryptik.FTW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNII
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Fragtor.41311
MicroWorld-eScanGen:Variant.Fragtor.41311
Ad-AwareGen:Variant.Fragtor.41311
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34266.@t0@aWFlKBkO
TrendMicroMal_Tofsee
FireEyeGeneric.mg.b40f5475117331b3
EmsisoftGen:Variant.Fragtor.41311 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen2
MicrosoftRansom:Win32/StopCrypt.MSK!MTB
GDataWin32.Trojan.PSE.YHQE1S
AhnLab-V3Ransomware/Win.Stop.R450422
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Kryptik!1.DA8B (CLASSIC)
YandexTrojan.Kryptik!FrmvvE+wTYg
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.DVL!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Fragtor.41311 (B)?

Fragtor.41311 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment