Trojan

Trojan:Win64/Grandoreiro!pz removal tips

Malware Removal

The Trojan:Win64/Grandoreiro!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Grandoreiro!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win64/Grandoreiro!pz?


File Info:

name: 5120F91404BB8387D290.mlw
path: /opt/CAPEv2/storage/binaries/7eed8dd8bfa4e8b3d232dd820e3111c06cbea723f3a4756d4986240dd8d1e482
crc32: 37A37AFD
md5: 5120f91404bb8387d290bbc8b80e2e54
sha1: 378d3290b7945c83ff9edc177009bb90476138b6
sha256: 7eed8dd8bfa4e8b3d232dd820e3111c06cbea723f3a4756d4986240dd8d1e482
sha512: e01b5bcfa8579d5014569e24dfca771aaea9e2b67f272b31ce05cf3b813cf35d27eea87eecc73cb4f95970a233f6cc1352be85af03459057b2eda6bfbb335e21
ssdeep: 384:A+Em3yWlEiMMMMMSAs+5B/kDE045HSUUUU:liMkMMMMSAs+n+AcUUUU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF523B3846EDD88AD5CD4EF3AB6EE8C381D93570563A84B9150FE80B0E59765FB3120E
sha3_384: fc636739c180c7b18746dd9cd8a938167fbe68c1761a18e1833733aeb04463eabfab0a21df4de0a1642af74cec942b0a
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win64/Grandoreiro!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.labP
MicroWorld-eScanTrojan.Ransom.Poison.B
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!5120F91404BB
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
AlibabaWorm:Win32/Grandoreiro.e3812b08
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.0b7945
ArcabitTrojan.Ransom.Poison.B
BitDefenderThetaAI:Packer.44249F861F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:v43qH4auAzMRAnr/x+krKA)
EmsisoftTrojan.Ransom.Poison.B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
TrendMicroTROJ_GEN.R03BC0DLI23
SophosMal/ExeSax-A
IkarusTrojan.Crypt
JiangminTrojan/Generic.bghcg
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
XcitiumHeur.Packed.MultiPacked@1z141z3
MicrosoftTrojan:Win64/Grandoreiro!pz
ViRobotTrojan.Win.Z.Poison.14336.WGOV
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
VaristW32/Agent.FJT.gen!Eldorado
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacTrojan.Ransom.Poison.B
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLI23
TencentTrojan.Win32.VB.kn
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win64/Grandoreiro!pz?

Trojan:Win64/Grandoreiro!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment