Ransom

Troj/Ransom-FRD removal guide

Malware Removal

The Troj/Ransom-FRD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Ransom-FRD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Troj/Ransom-FRD?


File Info:

crc32: 4F8F639B
md5: acf082c0c53d1e478f0048bac08d7a6d
name: 2c.jpg
sha1: 74d900a146e2475d2b1914b97f52d788232a596c
sha256: 379b874a71a6e1c10a55a38b8bdb4039004ac983553b16f483696b376b412eab
sha512: 7343d72d60c800f71b6c15b3e3579d0f05a1425a99f0897107567466332965695aa23050961b419d3739a2e85ede38c92c0c6ea9a0023db99834537ee34bdac7
ssdeep: 24576:PmelBWd6d6cLsmqnIyWJ3ob/giIoJ1Bl6KdZGqpADMTRi+vTwNSWPmIS47qcErx:eM8d6AcLCxJbRIo3HfGqmoTNrw3SBg
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Troj/Ransom-FRD also known as:

MicroWorld-eScanTrojan.GenericKD.32614774
CAT-QuickHealRansom.Stop.MP4
McAfeeTrojan-FRNO!ACF082C0C53D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00559bdb1 )
BitDefenderTrojan.GenericKD.32614774
K7GWTrojan ( 00559bdb1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_FRS.VSNW11J19
BitDefenderThetaGen:NN.ZexaF.33550.Nz0@aiaDDppi
F-ProtW32/Kryptik.AKQ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GXJX
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMC2.hp
AvastWin32:Malware-gen
ClamAVWin.Packed.Generic-7338654-0
GDataTrojan.GenericKD.32614774
KasperskyTrojan.Win32.Fsysna.fwfa
AlibabaTrojan:Win32/Fsysna.106d3cdd
NANO-AntivirusTrojan.Win32.Fsysna.gdyhcf
AegisLabTrojan.Multi.Generic.4!c
APEXMalicious
RisingTrojan.Kryptik!1.BDF7 (CLASSIC)
Ad-AwareTrojan.GenericKD.32614774
SophosTroj/Ransom-FRD
ComodoMalware@#27h10g48kp644
DrWebTrojan.Encoder.858
ZillyaTrojan.Kryptik.Win32.1791793
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
FireEyeGeneric.mg.acf082c0c53d1e47
EmsisoftTrojan-Ransom.Shade (A)
CyrenW32/Trojan.DKTR-8855
JiangminTrojan.Chapak.hfm
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1044490
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Fsysna
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F1A976
AhnLab-V3Malware/Win32.RL_Generic.R294867
ZoneAlarmTrojan.Win32.Fsysna.fwfa
MicrosoftTrojan:Win32/CryptInject.AS!MTB
Acronissuspicious
VBA32TrojanDownloader.Bandit
ALYacTrojan.Ransom.Shade
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
YandexTrojan.Fsysna!
IkarusTrojan.Win32.CryptInject
MaxSecureTrojan.Malware.74635621.susgen
FortinetW32/Kryptik.GXHG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.2.989F.Malware.Gen

How to remove Troj/Ransom-FRD?

Troj/Ransom-FRD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment