Categories: Ransom

How to remove “Ransom:MSIL/SPARTCRYPT.DA!MTB”?

The Ransom:MSIL/SPARTCRYPT.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/SPARTCRYPT.DA!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:MSIL/SPARTCRYPT.DA!MTB?


File Info:

crc32: 0042F6C0md5: 7061b29547de0ff55815eaa6eb4bee69name: 7061B29547DE0FF55815EAA6EB4BEE69.mlwsha1: 0d3daa028e99a7ba98a4fdd61ff9ed4efc96d82dsha256: 6cf1b18b34e5ff6fded9b19eaf393dc1016f5005175ff03e01e6f8b01674b855sha512: 9b446d507c3ff866ac163ab2dc5e207f9d4c3fff34e7a8ee0e79c9c659f693e24bb91917c26e6fedf623b846db51f80abf27e5057094e268d8dc407285aa945assdeep: 384:FV8aTE8qcSchXeQVbfANpCb8rMNCtpDkjvunItx4sOr3ibhrBvBkaqd7qasyO:FGaAHchXlb4qNFU1yr5uaeLsyOtype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Copyright 1999-2019 Chrome and Google developers. All rights reserved.Assembly Version: 47.24.11.2InternalName: Spart_E.exeFileVersion: 47.24.11.2CompanyName: LegalTrademarks: Comments: ProductName: ChromeProductVersion: 47.24.11.2FileDescription: ChromeOriginalFilename: Spart_E.exe

Ransom:MSIL/SPARTCRYPT.DA!MTB also known as:

K7AntiVirus Trojan ( 005597bc1 )
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.29792
Cynet Malicious (score: 100)
ALYac Trojan.Ransom.Filecoder
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.11174
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Ransom:Win32/Higuniel.d000b304
K7GW Trojan ( 005597bc1 )
Cybereason malicious.547de0
Cyren W32/Jigsaw.GEHI-8255
Symantec Trojan.Gen.MBT
ESET-NOD32 MSIL/Filecoder.Jigsaw.V
Zoner Trojan.Win32.85834
Avast Win32:RansomX-gen [Ransom]
Kaspersky HEUR:Trojan-Ransom.MSIL.Encoder.gen
BitDefender Trojan.AgentWDCR.XDL
NANO-Antivirus Trojan.Win32.Ransom.gimzaf
MicroWorld-eScan Trojan.AgentWDCR.XDL
Tencent Msil.Trojan.Encoder.Aexl
Ad-Aware Trojan.AgentWDCR.XDL
Sophos Mal/Generic-S + Mal/Generic-L
Comodo Malware@#20yakg1ywsrg7
BitDefenderTheta Gen:NN.ZemsilF.34688.bm0@ai5T2Om
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom.MSIL.SPARTCRYPT.A
McAfee-GW-Edition Ransom-SpartEnc!7061B29547DE
FireEye Trojan.AgentWDCR.XDL
Emsisoft Trojan.AgentWDCR.XDL (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.MSIL.ntwt
Webroot W32.Trojan.Gen
Avira TR/Jigsaw.canmb
Antiy-AVL Trojan/Generic.ASMalwS.2CFF7A5
Microsoft Ransom:MSIL/SPARTCRYPT.DA!MTB
AegisLab Trojan.MSIL.Encoder.j!c
GData Win32.Trojan.Agent.9OPMB3
AhnLab-V3 Malware/Win32.RL_Generic.C3540211
McAfee Artemis!7061B29547DE
MAX malware (ai score=100)
VBA32 TScope.Trojan.MSIL
Malwarebytes Ransom.SpartCrypt
Panda Trj/WLT.E
TrendMicro-HouseCall Ransom.MSIL.SPARTCRYPT.A
Rising Trojan.Phobos/HELP!1.BCC4 (KTSE)
Yandex Trojan.Filecoder!6eHKV4FjArY
Ikarus Trojan-Ransom.JigSaw
MaxSecure Trojan.Malware.73702460.susgen
Fortinet W32/Encoder.V!tr.ransom
AVG Win32:RansomX-gen [Ransom]
Paloalto generic.ml

How to remove Ransom:MSIL/SPARTCRYPT.DA!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

TrojanDownloader:Win32/Unruy.A removal instruction

The TrojanDownloader:Win32/Unruy.A is considered dangerous by lots of security experts. When this infection is active,…

37 seconds ago

Trojan:MSIL/Zusy.RDF!MTB removal guide

The Trojan:MSIL/Zusy.RDF!MTB is considered dangerous by lots of security experts. When this infection is active,…

44 seconds ago

About “Win32:Sality-KYG” infection

The Win32:Sality-KYG is considered dangerous by lots of security experts. When this infection is active,…

57 seconds ago

What is “Win32:VB-AACZ [Trj]”?

The Win32:VB-AACZ [Trj] is considered dangerous by lots of security experts. When this infection is…

21 mins ago

How to remove “Jalapeno.2990”?

The Jalapeno.2990 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dacic.1370.2522AF06 removal

The Generic.Dacic.1370.2522AF06 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago