Ransom

Should I remove “Ransom:Win32/GrandCrab.NAA!MTB”?

Malware Removal

The Ransom:Win32/GrandCrab.NAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GrandCrab.NAA!MTB virus can do?

  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/GrandCrab.NAA!MTB?


File Info:

crc32: 0328D210
md5: 105081b30042de273b94e7426910ad09
name: 105081B30042DE273B94E7426910AD09.mlw
sha1: d306f72532bda88dd1e10c253a2ca69bb107883e
sha256: d0d36a78f14667af93ddc8e0b56aee7f821fa902163147aa1e97a017c557a227
sha512: f3e665f4e14cecc198ccd55f454fe17251cfd5c66d4b98c5600125f6956974bcc0af33947ba9ddfa9b20d63fc8d72a6ec24a7d46e68231b72a5007701a79b05e
ssdeep: 1536:QD0M4fiuLiAtYIT21HEWW5ttUxL71c8AsWjcd7Z/0AftG3H:o0M0iSiACIKx1ZvN/0Aftc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GrandCrab.NAA!MTB also known as:

K7AntiVirusTrojan ( 005274f01 )
LionicTrojan.Win32.Scar.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.48995
MicroWorld-eScanGen:Variant.Zusy.343425
ALYacGen:Variant.Zusy.343425
CylanceUnsafe
ZillyaTrojan.Scar.Win32.108578
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 005274f01 )
Cybereasonmalicious.30042d
CyrenW32/S-1e0afec1!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.343425
NANO-AntivirusTrojan.Win32.Scar.eyblra
TencentMalware.Win32.Gencirc.114ce4ba
Ad-AwareGen:Variant.Zusy.343425
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.ZLLS@7l61f0
BitDefenderThetaGen:NN.ZexaF.34142.fuW@ae4CWVki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-HGK!105081B30042
FireEyeGeneric.mg.105081b30042de27
EmsisoftGen:Variant.Zusy.343425 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scar.lkg
AviraHEUR/AGEN.1117010
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.247F160
MicrosoftRansom:Win32/GrandCrab.NAA!MTB
GDataGen:Variant.Zusy.343425
AhnLab-V3Trojan/Win32.Scar.C2416120
McAfeeRansomware-HGK!105081B30042
MAXmalware (ai score=81)
VBA32Trojan.Scar
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.86 (RDML:BdtKt5oDjduEFKgSGxuzIQ)
YandexTrojan.GenAsa!PGhJWEB1hwQ
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ZLL!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/GrandCrab.NAA!MTB?

Ransom:Win32/GrandCrab.NAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment