Remove Gru Ransomware

Gru Ransomware is the name of a new file-locker that is being actively spread online. Its creators are relying on pirated content, fake downloads, and malicious ads to promote the dangerous download. Users who end up interacting with the Gru Ransomware may be in a lot of trouble. This threat can encrypt the majority of their files, and then extort them for a hefty ransom payment. In the case of the Gru Ransomware, the authors are asking for a compensation of $1,500, and they demand to receive the money via a Bitcoin transaction. Needless to say, you should not consider their offer – it would be easy for them to scam you since you will not have the ability to cancel the transaction. In addition to this, Gru Ransomware's creators seem to be very greedy - other file-lockers of this level, like the LOWPRICE Ransomware, ask for just a few hundred dollars.

read_it.txt Document Reveals the Demands of Gru Ransomware's Creators

The file types that the Gru Ransomware encrypts are numerous – documents, media, archives, databases, backups, and much more. After it locks a file, it appends the '.gru' extension next to its original name. The last action that the Gru Ransomware performs is to drop the document 'read_it.txt' on the desktop. It contains a ransom note, which urges the victim to pay the ransom fee. However, the message does not include contact details – it only lists the Bitcoin wallet of the criminals.

Gru Ransomware Ransom Note

Even if you pay them, it would be impossible to contact them to receive the decryptor. The Gru Ransomware does not come with a decryptor embedded in the payload, so it would be impossible for the decryption to start automatically. By the looks of it, the Gru Ransomware is a low-quality threat, which aims to steal money from ransomware victims.

Although the payload is still undergoing analysis, there is a chance that it might be based on the HiddenTear project. This may mean that the free HiddenTear decryptor is compatible with the Gru Ransomware – this is the data recovery option that victims should try first. Of course, before you try to undo the damage done to your files, you will need to eliminate the Gru Ransomware. The best way to do it is to run an up-to-date anti-malware scanner.

July 16, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.