Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2017

How to remove Gr3g ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

Gr3g ransomware is out on the hunt

The picture displaying Gr3g virus note

Gr3g virus functions as a file-encrypting threat. After finishing the encryption process, the malware appends .libbywovas@dr.com.gr3g file extension. It seems to be a new virus unassociated with any major ransomware group. On the other hand, its possible relation to HiddenTear should not be ignored.

At the moment, the virus only presents its ransom .txt file Readme.txt file. It informs victims that their files have been encoded. They have 96 hours to contact the perpetrators via libbywovas@dr.com. Here is the extract from the ransom note:

ATTENTION. To email (libbywovas@dr.com) write messages only from these e-mail services.
From other email services, messages may not be received by us.

Yahoo. https://mail.yahoo.com
Gmail. https://www.google.com
Mail. https://www.mail.com

ATTENTION. We will reply you within 24 hours. If there is no response from us, please send your message again.
Tor email: libbywovas@torbox3uiot6wchz.onion
To register tor e-mail, use the service http://torbox3uiot6wchz.onion (Open only to the tor browser).

In addition, the ransomware developers offer to decipher three files each smaller than 2MB to gain users’ trust.
Interestingly, Gr3g crypto-malware disguises under rasmans.exe file[1]. The file is associated with WinLAC company. Certain security services detect this file as malicious[2].

There is still little information about the malware. On another hand, if you detected some of your files with the above-mentioned extension, concentrate on Gr3g removal. FortectIntego or MalwarebytesMalwarebytes accelerates the process.

Ransomware prevention measures

According to IT specialists, the malware is quite active. At the moment, individual users are the main target. Ransomware are commonly distributed via the following three channels:

  • Spam email attachments
  • Exploit kits
  • Trojans
  • Browser extensions and apps

Regarding Gr3g ransomware, it seems to use the latter method as it disguises under an app. Likewise, pay utmost attention while installing any program. Make sure you download only signed applications by verified publishers. On the other hand, CCleaner v5.33 is a perfect illustrating sample that cyber villains can foist the malware in a legitimate and trusted program. In order to limit the risk of Gr3g hijack or other ransomware infiltration.The image of Gr3g ransom message and TorBox email service

Remove Gr3g malware properly

Since the malware still needs improvement, it is likely that you might not encounter difficulties getting rid of the threat. In order to begin Gr3g removal, you may need to reboot the system in Safe Mode. There is an alternative method.
After that, you should be able to access the security application and remove Gr3g virus completely.

At the moment, there is no information about Gr3g Decryptor. Until it is released, take a look at the alternative data recovery methods. You may also use backup copies. At the moment, the virus has been detected only in English[3] domains.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.