Ransom

About “Generic.Ransom.Spora.66B1B098” infection

Malware Removal

The Generic.Ransom.Spora.66B1B098 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Spora.66B1B098 virus can do?

  • Expresses interest in specific running processes
  • A process created a hidden window
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Exhibits possible ransomware file modification behavior
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Spora.66B1B098?


File Info:

crc32: A98F9903
md5: ea1e860b617a628b90322155a810584d
name: EA1E860B617A628B90322155A810584D.mlw
sha1: bc2e3908ca4adb4937a62039657f76b4ed9ab1f7
sha256: afb56d76554496c88c27f420e156924740dca48f9d2695dca568fa0852bdc027
sha512: 66815807bc914a029cb6661fef702ed1b8a365488520de29d8c1c6d25de49267024db18fad6952ef60705fded1c45ca2b9b0102f6009175fa76d626f524cbd02
ssdeep: 6144:vC64oXcQiaO/9mrjJK5wSINVPg41uzn4pP:vC6F0+3JwzIbgZOP
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Spora.66B1B098 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055b9671 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.47603
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Spora.66B1B098
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.13840
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055b9671 )
Cybereasonmalicious.b617a6
ESET-NOD32a variant of Win32/Filecoder.GandCrab.G
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.DelShad.gen
BitDefenderDeepScan:Generic.Ransom.Spora.66B1B098
NANO-AntivirusTrojan.Win32.DelShad.inowsi
MicroWorld-eScanDeepScan:Generic.Ransom.Spora.66B1B098
Ad-AwareDeepScan:Generic.Ransom.Spora.66B1B098
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34628.xuW@aKuGCCp
TrendMicroTROJ_GEN.R002C0PCN21
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.ea1e860b617a628b
EmsisoftDeepScan:Generic.Ransom.Spora.66B1B098 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DelShad.xz
AviraHEUR/AGEN.1133190
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult!ml
ArcabitDeepScan:Generic.Ransom.Spora.66B1B098
AegisLabTrojan.Win32.DelShad.4!c
GDataDeepScan:Generic.Ransom.Spora.66B1B098
Acronissuspicious
McAfeeRDN/Ransom
MAXmalware (ai score=82)
VBA32BScope.Trojan.DelShad
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PCN21
RisingRansom.ShadowCryptor!1.C536 (CLOUD)
IkarusTrojan.Win32.LockScreen
FortinetW32/GandCrab.G!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Spora.HgIASRUA

How to remove Generic.Ransom.Spora.66B1B098?

Generic.Ransom.Spora.66B1B098 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment