Trojan

Trojan:Win64/Grandoreiro!pz removal instruction

Malware Removal

The Trojan:Win64/Grandoreiro!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Grandoreiro!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win64/Grandoreiro!pz?


File Info:

name: 94FEFAEB2D8824D920C5.mlw
path: /opt/CAPEv2/storage/binaries/30ff637bc91de6043b8bbb9cb6918e03ca40e878ca2fc8164edfd15081df787a
crc32: 104CA44D
md5: 94fefaeb2d8824d920c580c28297d3cd
sha1: 55c6f8c18e8346392937299c89e43fedda143c5e
sha256: 30ff637bc91de6043b8bbb9cb6918e03ca40e878ca2fc8164edfd15081df787a
sha512: 1bed7f60e0a250dbd13e2546f73f9eb8bb9d6b13c114d42963432cc9b313208cfce836d3ab9489a3dd15a15f99f9dfbd4d72f24b19ff7ea7eba0e5fc67837a4c
ssdeep: 384:D1XPTDOg/q4eNBODQ5jwcXWf1CaiDE045H:D1XP/Og/qbNBODWjBdzA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153529E37289C16A0FD9D99F740F7C9CA54C1F1F12EAD8B5A840EA0BD0F05AE2556076B
sha3_384: d5a28f0af9595512ec86fc402ac717d9f52c92fe837f8ec4e29788b10324f67fca80a53bea0a0d78559f136e0ee22c19
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win64/Grandoreiro!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.124
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.94fefaeb2d8824d9
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!94FEFAEB2D88
MalwarebytesTrojan.Downloader
VIPRETrojan.Ransom.Poison.B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.18e834
BitDefenderThetaAI:Packer.44249F861F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.kn
EmsisoftTrojan.Ransom.Poison.B (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen
Trapminemalicious.high.ml.score
SophosMal/ExeSax-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.Ransom.Poison.B
JiangminTrojan/Generic.bghcg
VaristW32/Agent.FJT.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
MicrosoftTrojan:Win64/Grandoreiro!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
ALYacTrojan.Ransom.Poison.B
VBA32Malware-Cryptor.General.3
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDMK:SB7qJQ1EWqYvrnZwFMTgpw)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win64/Grandoreiro!pz?

Trojan:Win64/Grandoreiro!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment