Trojan

Trojan:Win32/Fragtor.ASFA!MTB malicious file

Malware Removal

The Trojan:Win32/Fragtor.ASFA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fragtor.ASFA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Trojan:Win32/Fragtor.ASFA!MTB?


File Info:

name: C35E0F19212CF3FA72B9.mlw
path: /opt/CAPEv2/storage/binaries/4bf05c7aa3dddb39c274099c0d4e75b4c646ddeadab8276cfea29375f9209e15
crc32: 6ABC69E0
md5: c35e0f19212cf3fa72b9965b34347688
sha1: 0c339acffb7e1af4b6cbb1b3398a97863efe48ef
sha256: 4bf05c7aa3dddb39c274099c0d4e75b4c646ddeadab8276cfea29375f9209e15
sha512: e5bb6342ecd28c4f991bd05fba543a2d927ec5619d1e58759b1c3edca5dfa81eb429ba5b9d6e960a72530b9449812fb3565fced11b66998622b270eddf9ca46e
ssdeep: 768:L42FIQ7w7Z22lPP3lLuzZPKq8Q3Ygn5Ri:L42+AyhlPP3lLuBZ8QIgq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D1E2C9A97E444CE7E560173C84E7C77A2A7CF151C6234B62F620B7349B337A5609B22E
sha3_384: 448a70920c99f14c350ca4e0c19d9c63627bb39330e13311938f33fe28a18089380423fa03375f382825ea1f32b2e7c3
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 13:50:05

Version Info:

0: [No Data]

Trojan:Win32/Fragtor.ASFA!MTB also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Fragtor.503163
FireEyeGeneric.mg.c35e0f19212cf3fa
CAT-QuickHealTrojan.Agent
SkyhighBehavesLike.Win32.Injector.nm
ALYacGen:Variant.Fragtor.503163
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Fragtor.18436f6d
K7GWTrojan ( 005b1a3e1 )
K7AntiVirusTrojan ( 005b1a3e1 )
ArcabitTrojan.Fragtor.D7AD7B
BitDefenderThetaGen:NN.ZedlaF.36744.c46@a0jyMfo
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ETQB
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fragtor.503163
NANO-AntivirusTrojan.Win32.AgentAGen.kjabfs
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.kbq
EmsisoftGen:Variant.Fragtor.503163 (B)
F-SecureTrojan.TR/Agent_AGen.cgzpq
VIPREGen:Variant.Fragtor.503163
TrendMicroTROJ_GEN.R023C0DBJ24
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
MAXmalware (ai score=80)
GoogleDetected
AviraTR/Agent_AGen.cgzpq
VaristW32/Agent.IHW.gen!Eldorado
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Fragtor.ASFA!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.10BOBTT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R634654
McAfeeGenericRXWN-OS!C35E0F19212C
VBA32BScope.Trojan.Fsysna
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R023C0DBJ24
RisingTrojan.Agent!8.B1E (TFE:5:oeTDpudt9WH)
YandexTrojan.Agent!NiluzIS41dQ
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.DDZ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Fragtor.ASFA!MTB?

Trojan:Win32/Fragtor.ASFA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment