Ransom

Ransom:Win32/GrandCrab.SA!MSR removal

Malware Removal

The Ransom:Win32/GrandCrab.SA!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GrandCrab.SA!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Anomalous binary characteristics

How to determine Ransom:Win32/GrandCrab.SA!MSR?


File Info:

crc32: 7176DC1D
md5: 6553b9502a1d4d2b336f85459e4d9339
name: 6553B9502A1D4D2B336F85459E4D9339.mlw
sha1: ea000e56b5c90f3920406f5423c4ac8e803d92bb
sha256: 53923323441e9e9a1506dd2730993520e8f323039e4c1a47602715b3a65a5b13
sha512: b1e0f8a694f174f4451afdc85d090da7ecee12b08528fda5c74fa94e80afb345b8e6ec3a1e8d2a13cca9ad6bcb723cdcef12d12978bad04765b30a0777fd36c0
ssdeep: 1536:pKXT6lkPQZLjCH0VQkWZ10Q9U2vnF2GsQxtivRBJQJVsWN5m1KwiZwNZCemQBRj:8PACH0VQkWZ67j82BJwV5xwiqNZLmQ7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GrandCrab.SA!MSR also known as:

BkavW32.FamVT.DisbukLZ.Trojan
K7AntiVirusTrojan ( 00532fd01 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacGen:Variant.Zusy.287607
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.4975
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GrandCrab.b4997b8c
K7GWTrojan ( 00532fd01 )
Cybereasonmalicious.02a1d4
CyrenW32/S-79ffeeec!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GHFR
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Phorpiex-9810805-1
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderGen:Variant.Zusy.287607
NANO-AntivirusTrojan.Win32.Encoder.fedfdj
ViRobotTrojan.Win32.GandCrab.95744
MicroWorld-eScanGen:Variant.Zusy.287607
TencentWin32.Trojan.Generic.Wnmh
Ad-AwareGen:Variant.Zusy.287607
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Magniber.FGH@7nyazg
BitDefenderThetaGen:NN.ZexaF.34678.fyW@aC9uYCci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.6553b9502a1d4d2b
EmsisoftGen:Variant.Zusy.287607 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.ds
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1103340
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/GrandCrab.SA!MSR
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Zusy.287607
AhnLab-V3Trojan/Win32.Gandcrab.R229506
Acronissuspicious
McAfeeGenericRXFP-BC!6553B9502A1D
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
RisingTrojan.Kryptik!1.B2AC (CLOUD)
IkarusTrojan-Ransom.GandCrab
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Ransom:Win32/GrandCrab.SA!MSR?

Ransom:Win32/GrandCrab.SA!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment