Backdoor

Backdoor:Win32/FR malicious file

Malware Removal

The Backdoor:Win32/FR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/FR virus can do?

  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:7718
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Backdoor:Win32/FR?


File Info:

crc32: B6AD2987
md5: 81fe7a2fa311132027ef812933fe4586
name: 81FE7A2FA311132027EF812933FE4586.mlw
sha1: ada66eafa1b4f19ec2a8c8fef654f93ec489fa55
sha256: e2af89f33c3a79e00a6cdd33820cceaba6702576255d4fff33e30d020243ea9c
sha512: b8138c6ad6b7eda48fd7d440c772b38b50629d6683307bdb38bd588dfa00f0f4f6df5dd575d34336193fc02e4159b9b2d48aaab335381f437fba2df584f4035d
ssdeep: 12288:zREPSooeoOzS+Evpzc6TdVXAMiDeIfl4xhD:zQSVeD/0pzc6XALc
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Glacier client
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 2.2.0.0
FileDescription:
OriginalFilename:
Translation: 0x0804 0x03a8

Backdoor:Win32/FR also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebBackDoor.GDoor.30
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.365892
CylanceUnsafe
SangforBackdoor.Win32.G_Door.b
AlibabaBackdoor:Win32/G_Door.b9573474
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fa3111
CyrenW32/Backdoor.QDIY-3229
SymantecBackdoor.G_Door.Client
ESET-NOD32Win32/G_Door.B
APEXMalicious
AvastFileRepMalware
KasperskyBackdoor.Win32.G_Door.b
BitDefenderGen:Variant.Ursu.365892
NANO-AntivirusTrojan.Win32.GDoor.dhmi
ViRobotBackdoor.Win32.G-Door.465408
MicroWorld-eScanGen:Variant.Ursu.365892
TencentMalware.Win32.Gencirc.10b658cc
Ad-AwareGen:Variant.Ursu.365892
SophosMal/Generic-R + Troj/Bdoor-FR
ComodoBackdoor.Win32.G_Door.B@15uu
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_GLACIER.A
McAfee-GW-EditionBackDoor-FR.a.cli
FireEyeGen:Variant.Ursu.365892
EmsisoftGen:Variant.Ursu.365892 (B)
JiangminBackdoor.G_Door.f
WebrootW32.Backdoor.Gen
AviraBDC/GDoor.300.Cli
eGambitGeneric.Backdoor
Antiy-AVLTrojan/Generic.ASMalwS.3B71E
KingsoftWin32.Hack.G_Door.b.(kcloud)
MicrosoftBackdoor:Win32/FR
GridinsoftBackdoor.Win32.Gen.cc!s2
ArcabitTrojan.Ursu.D59544
AegisLabTrojan.Win32.G.toOF
GDataGen:Variant.Ursu.365892
TACHYONTrojan/W32.Agent.1318912.BS
AhnLab-V3Win-Trojan/GDoor.Client_v22.B
McAfeeBackDoor-FR.a.cli
MAXmalware (ai score=99)
VBA32Backdoor.G_Door
PandaTrj/Binghe.Cli
TrendMicro-HouseCallBKDR_GLACIER.A
YandexTrojan.GenAsa!GV/OWf0HO+k
IkarusBackdoor.Win32.G_Door.B
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GDoor.B!tr.bdr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Backdoor:Win32/FR?

Backdoor:Win32/FR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment