Ransom

Should I remove “Generic.Ransom.Spora.E2F2B060”?

Malware Removal

The Generic.Ransom.Spora.E2F2B060 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Spora.E2F2B060 virus can do?

  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Spora.E2F2B060?


File Info:

name: DC769583C696EBE31CF9.mlw
path: /opt/CAPEv2/storage/binaries/62d8b64f33bd5a39893d7801872bf1d3577189a39caafbf3bbdfd0e7ace7d77d
crc32: 616B6378
md5: dc769583c696ebe31cf9d92c254bce1a
sha1: 38ff7ce4fa99988dde4f592036c8f74d4872adb3
sha256: 62d8b64f33bd5a39893d7801872bf1d3577189a39caafbf3bbdfd0e7ace7d77d
sha512: 5e34d7789b42c69122d03b875ceeb5b6cf5b545408ddc4358b9c6c16850937785bbf4960152c73a98c83a330d94af4def3d75d27ac6e8f3e7863b50830b3232f
ssdeep: 24576:7/AHsfaBp5LZ/RRtzddpRwwTGqnqDQdJRaUrdau8Bphm:MHsf01R7pRwwVqCXaEahBphm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12E359D30B992D077E56101F04FB8FA9A616DFD250F3546DFA7E40A2E6A304D24E32E67
sha3_384: 14050f1cc646bc12996d3c4ad3a67fa4537158b99134b83b6c8a4f356d32899d395fbbe417a852af015afba3b41c213b
ep_bytes: e8f20c0000e974feffffcccccccccc80
timestamp: 2022-05-02 22:30:36

Version Info:

CompanyName: Microsoft
FileDescription: Microsoft Protection Service
ProductName: Microsoft
Translation: 0x0409 0x04b0

Generic.Ransom.Spora.E2F2B060 also known as:

MicroWorld-eScanDeepScan:Generic.Ransom.Spora.E2F2B060
FireEyeDeepScan:Generic.Ransom.Spora.E2F2B060
ALYacDeepScan:Generic.Ransom.Spora.E2F2B060
Cybereasonmalicious.3c696e
ArcabitDeepScan:Generic.Ransom.Spora.E2F2B060
BitDefenderThetaAI:Packer.6A3BFE081C
CyrenW32/ABRansom.QNHR-4258
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.OIF
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Spora.E2F2B060
CynetMalicious (score: 100)
AvastWin32:RansomX-gen [Ransom]
TencentWin32.Trojan.Filecoder.Wtni
Ad-AwareDeepScan:Generic.Ransom.Spora.E2F2B060
EmsisoftDeepScan:Generic.Ransom.Spora.E2F2B060 (B)
VIPREDeepScan:Generic.Ransom.Spora.E2F2B060
McAfee-GW-EditionGenericRXSU-TJ!DC769583C696
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
JiangminTrojan.DelShad.brc
AviraHEUR/AGEN.1250675
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDeepScan:Generic.Ransom.Spora.E2F2B060
GoogleDetected
AhnLab-V3Ransomware/Win.Cryptolocker.C4851941
McAfeeGenericRXSU-TJ!DC769583C696
MAXmalware (ai score=81)
VBA32BScope.Exploit.Convagent
MalwarebytesRansom.Spora
RisingRansom.RCRU!1.DDE5 (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.OIE!tr.ransom
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Generic.Ransom.Spora.E2F2B060?

Generic.Ransom.Spora.E2F2B060 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment