Risk

WinGo/Riskware.Frp.G removal tips

Malware Removal

The WinGo/Riskware.Frp.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Riskware.Frp.G virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine WinGo/Riskware.Frp.G?


File Info:

name: ACA084A3F3D8E20B6AA2.mlw
path: /opt/CAPEv2/storage/binaries/a240c9a07e90f4d2da7b01502d272f7fa4fb4c8f1527e1b309fe57f6a2218077
crc32: 70DFACFB
md5: aca084a3f3d8e20b6aa24db8d4513dd0
sha1: b541fbed50236bbdedfe600aff8ccfb7c0cea431
sha256: a240c9a07e90f4d2da7b01502d272f7fa4fb4c8f1527e1b309fe57f6a2218077
sha512: a6ddb670ad7ca16a7808f13fc985a1a850415aea222f1f200759cd7e50e166e6384a1a216abf5cf04851a948c50ac332dd9c3f35bdd9eec689b570c47b8c5989
ssdeep: 49152:bZQZU5rmAIgEY01wVIEmXUopyqaW7M+dfAgcKZ37YKIjsIuq0pEIYQeisYBlR8IN:qG5SJvY0CVIEyfyV2ADKdYKIIqQEmFzt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11DE533C5433730D8C5A0DEF2B89D1C87D01A7E013D6617BA2B2F584E63BAB95B5896C3
sha3_384: b63432a584330d53dcbc198ec47fd7dd4a8b0f25918c461ae2e19beabac769fd025771556e321cecefd6665cc90ff874
ep_bytes: 60be15209d008dbeebefa2ff5783cdff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

WinGo/Riskware.Frp.G also known as:

LionicRiskware.Win64.FRP.1!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
McAfeeArtemis!ACA084A3F3D8
SangforHacktool.Win64.FRP.cn
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaNetTool:Win64/Generic.15930424
K7GWTrojan ( 0057f0a51 )
K7AntiVirusTrojan ( 0057f0a51 )
SymantecFastReverseProxy
ESET-NOD32a variant of WinGo/Riskware.Frp.G
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9857179-0
Kasperskynot-a-virus:NetTool.Win64.FRP.cn
BitDefenderGen:Variant.Graftor.944318
MicroWorld-eScanGen:Variant.Graftor.944318
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Graftor.Lpuu
Ad-AwareGen:Variant.Graftor.944318
EmsisoftGen:Variant.Graftor.944318 (B)
ZillyaTool.Frp.Win32.65
TrendMicroTROJ_GEN.R002C0WCF22
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGen:Variant.Graftor.944318
SophosFast Reverse Proxy (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.944318
JiangminNetTool.FRP.g
MAXmalware (ai score=85)
ArcabitTrojan.Graftor.DE68BE
ZoneAlarmnot-a-virus:NetTool.Win64.FRP.cn
MicrosoftProgram:Win32/Wacapew.C!ml
AhnLab-V3Trojan/Win32.Wacatac.C4190983
ALYacGen:Variant.Graftor.944318
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0WCF22
RisingHacktool.Frp!8.1336B (CLOUD)
YandexRiskware.NetTool!IGiXPJnzys0
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Frp
AVGFileRepMalware [Misc]
PandaTrj/CI.A

How to remove WinGo/Riskware.Frp.G?

WinGo/Riskware.Frp.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment