Malware

UDS:NetTool.Win64.FRP removal tips

Malware Removal

The UDS:NetTool.Win64.FRP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:NetTool.Win64.FRP virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine UDS:NetTool.Win64.FRP?


File Info:

name: 9889AE089D67594F3C01.mlw
path: /opt/CAPEv2/storage/binaries/397cb247688107ed760fbe02c29f3d28e0ce418dae928eb030789a9954de404c
crc32: 2561509F
md5: 9889ae089d67594f3c019e5332e433f6
sha1: 991580647878b17f7beb856f05f56d152e1f96d4
sha256: 397cb247688107ed760fbe02c29f3d28e0ce418dae928eb030789a9954de404c
sha512: af841dd736b9d947a857809dda8b70b01ea969d46e1487531ad17e6eea19214f47dfb40f89d66c70b44732a615b57c9e268eb76f937974918cd572dff8b634ef
ssdeep: 196608:Zv6+wrlP+6psZt2N5NxUxVrPCO0ynNGsI3hihe4hp:ZvwrlP3qZcNYVrPCO0OBS8e4hp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B59633175D286DFFC0248436193386D76EE7BE22912A69B1C741AF4BC838670E7DB742
sha3_384: c21c137e4eab15b865869e3d82ed749d7d37f3cb7a0f1f0bf7b0ff0ff6eed2fc24ba0b801a69f6890c0fef33be1ec85a
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-12-15 22:24:41

Version Info:

Comments: Free VPN for Windows
CompanyName: Free VPN
FileDescription: Free VPN for Windows
FileVersion: 0.99.4.0
LegalCopyright: Free VPN
ProductName: Free VPN
ProductVersion: 0.99.4.0
Translation: 0x0409 0x04e4

UDS:NetTool.Win64.FRP also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win64.FRP.1!c
Elasticmalicious (moderate confidence)
CAT-QuickHealTrojan.Frp
SkyhighBehavesLike.Win32.Dropper.rc
McAfeeArtemis!9889AE089D67
Cylanceunsafe
ZillyaTool.FRP.Win64.2
SangforHacktool.Win64.FRP.gen
AlibabaTrojan:Win32/Frp_go_tool.a62850f6
K7GWTrojan ( 0056e5201 )
K7AntiVirusTrojan ( 0056e5201 )
BitDefenderThetaGen:NN.ZexaE.36804.xCW@aOKBqsni
ESET-NOD32multiple detections
AvastWin32:PUP-gen [PUP]
Kasperskynot-a-virus:UDS:NetTool.Win64.FRP.gen
F-SecureAdware.ADWARE/Redcap.dfaui
TrendMicroPUA.Win32.VPNWholesaler.A
SophosFast Reverse Proxy (PUA)
IkarusPUA.RiskWare.Frp
Antiy-AVLGrayWare[AdWare]/Win32.VPNWholesaler
MicrosoftPUA:Win32/Vigua.A
ZoneAlarmnot-a-virus:HEUR:NetTool.Win64.FRP.gen
VaristW32/ABApplication.KUAS-4527
MalwarebytesGeneric.Adware.Agent.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CBA24
RisingTrojan.Generic@AI.89 (RDML:N+PWDNsAIgZFJcJuyJQ3bg)
YandexTrojan.Igent.bWCwEw.22
FortinetRiskware/BURNTCIGAR
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS

How to remove UDS:NetTool.Win64.FRP?

UDS:NetTool.Win64.FRP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment