Trojan

About “Trojan:Win64/Grandoreiro!pz” infection

Malware Removal

The Trojan:Win64/Grandoreiro!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Grandoreiro!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win64/Grandoreiro!pz?


File Info:

name: 7609DF4FD8BAAC198125.mlw
path: /opt/CAPEv2/storage/binaries/13ccbd087b22203def8edba62e23fa97a8e2cdc0656cfd22c28b3971bae3756f
crc32: 4120CBB8
md5: 7609df4fd8baac198125b0e4e143ea05
sha1: 40f088cf886a8d7fb72328894d6f588fb93c513f
sha256: 13ccbd087b22203def8edba62e23fa97a8e2cdc0656cfd22c28b3971bae3756f
sha512: 9d19692e235854c704c2ca0ec7b941c9c3bbd4c6aec71e71d22bf10f348a10a8e65bb985402c4e33ee599310da27925910492f1c0c6c700bba843e042435272b
ssdeep: 192:bm62gNeYcNWLB0uYGk4aQIJ+WeIiyw6J2s/foC/6/Jo2Ato2GuqDE045HQNVjYVH:Ki46iubk4aQVWeaw68flAtbADE045H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA52AE741A1D8877FEDE4FF7C17120CA14A6B4611EF749608A17F0AD9F3A6195B80B03
sha3_384: 0fbe72567728112c108ae1a755adb52bc9a7e24dbcb91f2bb12cfdb89b4d07ed5f2386c28baf79e7f742115338eb486e
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win64/Grandoreiro!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.7609df4fd8baac19
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!7609DF4FD8BA
MalwarebytesTrojan.Downloader
ZillyaTrojan.ConvagentGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.fd8baa
VirITTrojan.Win32.AgentT.DXV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:Trojan.Win32.VB.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.kn
EmsisoftTrojan.Ransom.Poison.B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
Trapminemalicious.high.ml.score
SophosMal/ExeSax-A
IkarusTrojan.Crypt
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Agent.FJT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win64/Grandoreiro!pz
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:Trojan.Win32.VB.gen
GDataTrojan.Ransom.Poison.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
BitDefenderThetaAI:Packer.44249F861F
ALYacTrojan.Ransom.Poison.B
MAXmalware (ai score=83)
VBA32Malware-Cryptor.General.3
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDMK:ZR9qd4MaYWndaC0Te/Ou0Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Obfuscate.SMC.Hep(dyn)

How to remove Trojan:Win64/Grandoreiro!pz?

Trojan:Win64/Grandoreiro!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment