Trojan

Should I remove “Trojan:Win32/Fragtor.ASFA!MTB”?

Malware Removal

The Trojan:Win32/Fragtor.ASFA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fragtor.ASFA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Trojan:Win32/Fragtor.ASFA!MTB?


File Info:

name: 4CA5CD2AEF78ADBB3BD2.mlw
path: /opt/CAPEv2/storage/binaries/03c8c390f6c30b928382d3ffb1e6ebc49a6ea756b5e7c4c6d1b8db1eb3c42878
crc32: 6742CDE4
md5: 4ca5cd2aef78adbb3bd2ea45dc90f9ed
sha1: a63d89e316b2a0df35d855fdc7d58622d99ca834
sha256: 03c8c390f6c30b928382d3ffb1e6ebc49a6ea756b5e7c4c6d1b8db1eb3c42878
sha512: 85d82596d1d30d47f41cd925506949503d2dc4958a1d8f96712479eb9f39a4978fd38750a37f21bb3f6bdeb4fb4f20e0b3e9acb47fa34d178ffb288ea4a63ad3
ssdeep: 384:3t/ybvEbMlSnvtClfDTmPeuaBU3losjuzZ6UwYRGZqQ7PN4bXKpE/GZcjul/xRi:MbYMYt0OPP3lLuzZPKqom6oGeju1xRi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1E9E2E999BE444CE7D5511B3880F7CB762A7DF151C6234B62F660E7348A337A2209B27E
sha3_384: d1cad5183862d54f0014a7d058e2370be0d57934988119893d154c599b55add01e2deba99b1f9e024ef3b697bfa7585c
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 13:50:35

Version Info:

0: [No Data]

Trojan:Win32/Fragtor.ASFA!MTB also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.503136
FireEyeGen:Variant.Fragtor.503136
CAT-QuickHealTrojan.IGENERIC
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OS!4CA5CD2AEF78
MalwarebytesTrojan.Injector
VIPREGen:Variant.Fragtor.503136
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b1a3b1 )
AlibabaTrojan:Win32/Fragtor.477ced40
K7GWTrojan ( 005b1a3b1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ETQB
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fragtor.503136
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.14014f5b
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R03FC0DBJ24
EmsisoftGen:Variant.Fragtor.503136 (B)
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.10BOBTT
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Fragtor.D7AD60
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Fragtor.ASFA!MTB
VaristW32/Agent.IHW.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R634466
BitDefenderThetaGen:NN.ZedlaF.36744.c46@aK!@5rd
ALYacGen:Variant.Fragtor.503136
MAXmalware (ai score=88)
VBA32BScope.Trojan.Fsysna
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09BB24
RisingTrojan.Agent!8.B1E (TFE:5:pvdOvhVxApJ)
YandexTrojan.Agent!gOftu9ZBLzM
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.DDZ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Fragtor.ASFA!MTB?

Trojan:Win32/Fragtor.ASFA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment