Trojan

Trojan:Win64/Grandoreiro!pz removal tips

Malware Removal

The Trojan:Win64/Grandoreiro!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Grandoreiro!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win64/Grandoreiro!pz?


File Info:

name: 7CBF1D0D3338291956AA.mlw
path: /opt/CAPEv2/storage/binaries/cac01769f1e8226bc1d6ba27867d47385487512e1d0a7e76de70f569dff6e067
crc32: 3701C4AB
md5: 7cbf1d0d3338291956aa33b1c50079fc
sha1: 5bf8c88720bcca538cf1092d1bf1c23d1036436c
sha256: cac01769f1e8226bc1d6ba27867d47385487512e1d0a7e76de70f569dff6e067
sha512: 1b2f3aaf05c8b81305f117b3f63626e55437c8cca63f4c189162a60c39a60f145774e77a60789184ec35009e044bb1b999ec5b7775599a14c4939d5185b8178c
ssdeep: 384:x+J7waxtMhSaYux5+ThlklYhVLPGlQTQDE045H1vWvWvWvW:xxC+kklYDPkqqA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D527D7716BC06EAFA1C22F700B641E11651BBA32A8D425D272EE06C4FE60071B3672B
sha3_384: da3c1225ea5235a23c1bd1498718ac7e266bd6e971832b32f80d0fa9d4044abae998b9ce67890ea45ba2ced431777d27
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win64/Grandoreiro!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.7cbf1d0d33382919
SkyhighBehavesLike.Win32.Generic.lc
ALYacTrojan.Ransom.Poison.B
MalwarebytesTrojan.Downloader
ZillyaTrojan.ConvagentGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
BitDefenderTrojan.Ransom.Poison.B
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.d33382
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:Trojan.Win32.VB.gen
NANO-AntivirusTrojan.Win32.VB.juiskq
RisingTrojan.Generic@AI.100 (RDML:O3BcAugFMgMbq7wqhBmmPA)
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
TrendMicroTROJ_GEN.R03BC0DCF24
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Poison.B (B)
IkarusTrojan.Crypt
GDataTrojan.Ransom.Poison.B
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Agent.FJT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:Trojan.Win32.VB.gen
MicrosoftTrojan:Win64/Grandoreiro!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
McAfeeGenericRXTL-LJ!7CBF1D0D3338
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.General.3
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DCF24
TencentTrojan.Win32.VB.kn
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.C40A!tr
BitDefenderThetaAI:Packer.44249F861F
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirTool:Win/Obfuscate.SMC.Hep(dyn)

How to remove Trojan:Win64/Grandoreiro!pz?

Trojan:Win64/Grandoreiro!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment