How to remove ndfsr.exe

ndfsr.exe

The module ndfsr.exe has been detected as Ransom.Wacatac

ndfsr.exe
Product Name:

GeoGebra Classic

Company Name:

International GeoGebra Institute

MD5: 3a4a0a193efe53ea3a51823442c46b13
Size: 3 MB
First Published: 2020-06-21 13:28:39 (4 years ago)
Latest Published: 2020-06-30 12:07:22 (4 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2020-06-30 12:07:22 (4 years ago)
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
26.7%
26.7%
13.3%
13.3%
6.7%
6.7%
6.7%
Windows 10 77.8%
Windows Server 2012 R2 16.7%
Windows 8.1 5.6%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x004299b9

PE Sections:

Name Size of data MD5
.text 0 00000000000000000000000000000000
.rdata 0 00000000000000000000000000000000
.data 0 00000000000000000000000000000000
.vmp0 0 00000000000000000000000000000000
.vmp1 3319808 250a7f51bb4ecb0149afe42818bf7c69
.rsrc 454144 f2e0ad8c48140f6029effa4c7b68ba0f

More information:

Download GridinSoft Anti-Malware - Removal tool for ndfsr.exe