How to remove ndfsr.exe

ndfsr.exe

The module ndfsr.exe has been detected as Ransom.Wacatac

ndfsr.exe
Product Name:

GeoGebra Classic

Company Name:

International GeoGebra Institute

MD5: e6252b907aa51b98340542b89fcd445e
Size: 3 MB
First Published: 2020-06-22 05:06:05 (4 years ago)
Latest Published: 2020-06-23 06:37:26 (4 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2020-06-23 06:37:26 (4 years ago)
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
20.0%
15.0%
15.0%
10.0%
10.0%
10.0%
5.0%
5.0%
5.0%
5.0%
Windows 10 81.0%
Windows 7 19.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0043344f

PE Sections:

Name Size of data MD5
.text 0 00000000000000000000000000000000
.rdata 0 00000000000000000000000000000000
.data 0 00000000000000000000000000000000
.vmp0 0 00000000000000000000000000000000
.vmp1 3328512 0e42e7da38ff59af852923bd423f1b67
.rsrc 454144 784e2f132b38284856d71463686d8dbb

More information:

Download GridinSoft Anti-Malware - Removal tool for ndfsr.exe