Ransom

How to remove “Ransom:Win32/Grymegat.A”?

Malware Removal

The Ransom:Win32/Grymegat.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Grymegat.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/Grymegat.A?


File Info:

name: 842511B03413CD130232.mlw
path: /opt/CAPEv2/storage/binaries/7d76b0b2e877a41f1feffb3452e95f78112414041a9c4d288c695461822cb392
crc32: C4802471
md5: 842511b03413cd13023266d9e7c385f7
sha1: a5242b45e81cc36942fc17731180675fe045d04c
sha256: 7d76b0b2e877a41f1feffb3452e95f78112414041a9c4d288c695461822cb392
sha512: aaff0ce25eac61f10df7241be07ea2e919909ba9f1d719dcf74cdb77a25c296e957c259eb8bea4d625dd08e0122e0865c96289146142f7ab5d9fcb1807a6b131
ssdeep: 3072:vbLXOPbZKULLXmw3fvclIAsktvsx4wxpqH5W5j:vn+PFKULLXmwPCAktvtwoC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185148E53B2D08D76D0B50B3C8CDAA3757639FE811E2E2667B2ED671D4D3928209983D2
sha3_384: 1fda12d169e9adb9029097d95ba5229de54a93dc20275091be1a48aed147ec7e14385ce99854876e5e18a4cc06f99557
ep_bytes: 558becb9080000006a006a004975f953
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ransom:Win32/Grymegat.A also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
McAfeeArtemis!842511B03413
Cylanceunsafe
SangforTrojan.Win32.Save.a
BitDefenderTrojan.GenericKD.67437013
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Virtumonde.BD.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Publedl.A
APEXMalicious
ClamAVWin.Packed.Zbot-7437352-0
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.TrjGen.cehzvv
RisingDownloader.Wintrim!8.92D (TFE:1:WOg3NZ32erD)
SophosMal/Generic-S
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Winlock.7276
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.842511b03413cd13
JiangminTrojan/Generic.altus
GoogleDetected
AviraBDS/Backdoor.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Unknown
MicrosoftRansom:Win32/Grymegat.A
ZoneAlarmUDS:DangerousObject.Multi.Generic
CynetMalicious (score: 100)
VBA32Trojan.Genome.am
MalwarebytesMalware.AI.737807877
PandaGeneric Malware
TencentWin32.Backdoor.Backdoor.Aujl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Vundo.SO!tr
BitDefenderThetaGen:NN.ZelphiF.36250.muW@aq5bWZd
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]

How to remove Ransom:Win32/Grymegat.A?

Ransom:Win32/Grymegat.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment