Ransom

What is “Generic.Ransom.Spora.1C775103”?

Malware Removal

The Generic.Ransom.Spora.1C775103 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Spora.1C775103 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Vietnamese
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware

Related domains:

wckrqjhbdvxy.work
pbdbelcmiobays.xyz
gcpkonoxchig.work
pxctehgaptvuw.biz
fmvscvxjxpxuivh.org
ltcqdinlclww.org
haxjqaq.pw
txmkmpwwotqq.biz
iqudkmv.click
ppgqntfincc.ru
hoxxwaqtwif.biz
eqhvsddk.pw

How to determine Generic.Ransom.Spora.1C775103?


File Info:

crc32: E2EC5652
md5: 40557ef1d49c8ca18bdfeb6533c17e1e
name: 40557EF1D49C8CA18BDFEB6533C17E1E.mlw
sha1: c022393a2808b31f1e3f386046e17f6226d2780e
sha256: 7ec982d667aee8fa973d4a61ca8d9fa12cfac473ab5a2fa720ce46a96e3dc053
sha512: c4c0064aa73fa228718390c8eb0462285446cd0c66f4084c7ca4e4a53215a31b299abaec4c35d9c0aa2ff4afbb2b99094c19580df0a81637f981b3f3d8d04e96
ssdeep: 3072:N+oB5yE9UzS7iROx/8BEVaBgJGkTRv6k0LC14Ep7m1cKJ1PARCAe:coXOzS+ROt8IlJG+P1HXY9A0V
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012
InternalName: Pointers
FileVersion: 148, 172, 224, 211
CompanyName: Marek Jasinski - www.freeCommander.com
ProductName: Proofing Postman
ProductVersion: 3, 140, 76, 4
FileDescription: Multiplexing

Generic.Ransom.Spora.1C775103 also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
DrWebTrojan.DownLoader19.56612
CynetMalicious (score: 100)
CAT-QuickHealRansom.Teslacrypt.OL4
ALYacDeepScan:Generic.Ransom.Spora.1C775103
CylanceUnsafe
ZillyaTrojan.CryptGen.Win32.1
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.1d49c8
SymantecRansom.Cryptolocker
ESET-NOD32Win32/Filecoder.Locky.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Spora.1C775103
NANO-AntivirusTrojan.Win32.Dwn.ebuptb
ViRobotTrojan.Win32.Locky.Gen.C
MicroWorld-eScanDeepScan:Generic.Ransom.Spora.1C775103
TencentWin32.Trojan.Filecoder.Ozrx
Ad-AwareDeepScan:Generic.Ransom.Spora.1C775103
SophosML/PE-A + Troj/Ransom-CYD
BitDefenderThetaGen:NN.ZexaF.34142.kq0@aevOUUdO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SM1
McAfee-GW-EditionRansomware-FHI!40557EF1D49C
FireEyeGeneric.mg.40557ef1d49c8ca1
EmsisoftDeepScan:Generic.Ransom.Spora.1C775103 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Waldek.clt
WebrootW32.Gen.BT
AviraHEUR/AGEN.1113902
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASBOL.382E
KingsoftWin32.Troj.Waldek.h.(kcloud)
MicrosoftRansom:Win32/Locky.A
ArcabitDeepScan:Generic.Ransom.Spora.1C775103
GDataDeepScan:Generic.Ransom.Spora.1C775103
AhnLab-V3Win-Trojan/Lockycrypt.Gen
McAfeeRansomware-FHI!40557EF1D49C
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPLOCKY.SM1
RisingTrojan.Generic@ML.100 (RDML:ZLToRbI3EhgL5+pzw2TBEg)
YandexTrojan.Waldek!duIB9/HD1BA
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ESPA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Spora.1C775103?

Generic.Ransom.Spora.1C775103 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment