Trojan

Trojan:Win64/Grandoreiro!pz (file analysis)

Malware Removal

The Trojan:Win64/Grandoreiro!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Grandoreiro!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win64/Grandoreiro!pz?


File Info:

name: 6B9CB40A7DDA8BA7B7ED.mlw
path: /opt/CAPEv2/storage/binaries/6ea030d74a1e157b72bff5821b576e59454a2edc8065cae7f3deb128d87baf9c
crc32: A6F2162B
md5: 6b9cb40a7dda8ba7b7edb9f09557a30c
sha1: 7aa44af0f7c360e236e28a7b63d6394a23137908
sha256: 6ea030d74a1e157b72bff5821b576e59454a2edc8065cae7f3deb128d87baf9c
sha512: 77aa77df9d6dcda9073d99683faff52cc50586d0a330991125ae44698e7c9d9be0069cdc8b2760657bfae1910c30e07ee914714ef7cbffcf71319d72c0bb665f
ssdeep: 384:pB+u7lx4aWZVBJiRB91G82SUHhNRy4DE045H:pZCakVBJiZ1gtjA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133529D35359DA2F1FA0C0BFB0623C7C239E5792487D4248D05CFE6C74E3A65526A2B0B
sha3_384: eaad08a65c89b6238cd7d73531cb0a3ad9f96d9c630298c0a5016358990487688c0c9aa1b1030423316e5b656d50741a
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win64/Grandoreiro!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.6b9cb40a7dda8ba7
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!6B9CB40A7DDA
MalwarebytesTrojan.Downloader
ZillyaTrojan.ConvagentGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
K7GWTrojan ( 0059befd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.44249F861F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.kn
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Poison.B (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Agent.FJT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Krap.cku
MicrosoftTrojan:Win64/Grandoreiro!pz
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
VBA32Malware-Cryptor.General.3
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDMK:ZZNQIe0YwPQdwC7K+C1H8g)
IkarusTrojan.Crypt
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a7dda8
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Obfuscate.SMC.Hep(dyn)

How to remove Trojan:Win64/Grandoreiro!pz?

Trojan:Win64/Grandoreiro!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment