Grandeur Ransomware - How to remove

Grandeur is a malicious program that encrypts data and asks for money to fix it. When Grandeur infects a computer, it encrypts files and changes their names, ending them with file type extension “grandeur”. Encrypted files can’t be opened and read and there is no easy way to fix them.

There’s no way to decrypt files encrypted by Grandeur for free, though there are a few other options that are worth looking into. But the best way to protect yourself against ransomware is by backing up your data regularly.

About Grandeur ransomware:

Type of threat Ransomware.
How Grandeur infects computers It spreads through Remote Desktop accounts,

it deletes backups and encrypts files.

Can encrypted files be fixed? Restore data from backups,

recover or repair some data,

keep the encrypted data in case a decryption solution emerges.

How to delete Grandeur Find and delete malware with antivirus programs (Spyhunter, others),

reset your credentials to avoid repeat infection.

How does Grandeur ransomware work?

RDP hacks and other infection methods

Grandeur ransomware is a type of VoidCrypt ransomware.

Ransomware infections spread with malicious emails, pirated software, and very often, they are installed remotely by criminals who hacked an RDP account. Maybe the account had a weak password, or maybe an unknown or unpatched vulnerability was used, but remote desktop protocol is often abused by cybercriminals to spread malware.

Another option is a backdoor – a previously installed malicious program that allows cybercriminals to control the infected computer, for example, download a malicious file.

Grandeur ransom note asks for Bitcoin.

Symptoms of the infection

Grandeur is file-locking ransomware. It encrypts the files on the device so that their contents are corrupted. These files don’t open.

Grandeur also changes the names of the files by adding an email address, an id, and an extension “grandeur”:

[original file name].[email][id].grandeur

The id in the names of the encrypted files is made up of random letters and numbers.

In addition to locking files, Grandeur does a few more things to make life harder for the victim:

  • deletes backups to stop the victim from restoring earlier file versions,
  • it can disable Task Manager and security programs,
  • it might cause various errors, such as user profile, file permission errors.

Grandeur creates ransom notes called Decrypt-me.txt.

All Your Files Has Been Encrypted

You Have to Pay to Get Your Files Back

1-Go to C:\ProgramData] folder  and send us prvkey*.txt.key  file , * might be a number (like this : prvkey3.txt.key)

2-You can send some file little than 1mb for Decryption test to trust us But the test File should not contain valuable data

3-Payment should be with Bitcoin

4-Changing Windows without saving prvkey.txt.key file will cause permanete Data loss

Our Email:[email address]

in Case of no Answer:[email address]

How to delete Grandeur ransomware

Can you recover your files?

First, it’s important to decide what you want to do with the encrypted files.

If you have a backup of your data, then you only need to clean your computer and then restore the backups.

But if you don’t have backups or if they were caught by Grandeur, then the situation is a bit more complicated. You might be able to recover or repair some data, but there’s no free solution to fix the files that Grandeur encrypted.

You could keep the encrypted files, see if a solution emerges. Sometimes cybercriminals (or law enforcement) release master decryption keys. Check Nomoreransom.org – that’s where free decryption tools are listed.

And paying the ransom that the criminals are asking is risky – the decryptor provided by the criminals might have errors (such as with decrypting large files), or there might be technical issues. VoidCrypt is often reported to cause technical problems.

How to delete malware

Antivirus scanners flag Grandeur and other VoidCrypt ransomware as Ransom, Maliciousm AmnesiaE, Ouroboros, Trojan, VoidCrypt, and other names.

You can reset your PC to get rid of the malware, or you can use an antivirus program (such as Spyhunter). Grandeur should delete itself, but other malicious files might still remain.

Once all malware is gone, make sure that the infection won’t repeat. Use strong Remote Desktop credentials and 2-factor authentication.

Most importantly, have a backup of your data. Backups are the best way to protect yourself from ransomware.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,


How to recover Grandeur Ransomware encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode
 

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before Grandeur Ransomware has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3
 

Step 2. Complete removal of Grandeur Ransomware

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to Grandeur Ransomware. You can check other tools here.  

Step 3. Restore Grandeur Ransomware affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually Grandeur Ransomware tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover Grandeur Ransomware encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *