Ransom

Ransom:Win32/Spora.B removal instruction

Malware Removal

The Ransom:Win32/Spora.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Spora.B virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Spora.B?


File Info:

crc32: FADC12C3
md5: 2fe46a2c73243bba49ffa20c34657fd3
name: 2FE46A2C73243BBA49FFA20C34657FD3.mlw
sha1: 02009aba88725eb5b1b05bd8f521c4b0b586ac1d
sha256: f1894094b99c11bba0e0f8102b40472af69fa95a451a16d6ba979dd2a9789721
sha512: 6f03b9d81bb85644c9ea513485569729e134b1c0d189e146275fbca326ead02ce85d0c572d814b5837ec7621205367bb81bf4275fc14246519772b4b5f54bad3
ssdeep: 1536:VNtX0eXqhBRtcBThEOgCa4OAW+aAmCgbdQZDTCzGPB:ZhsBR2BTh1gCa13i+zG5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Spora.B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.40027
FireEyeGeneric.mg.2fe46a2c73243bba
CAT-QuickHealRansom.Spora
ALYacTrojan.GenericKDZ.40027
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.40027
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c73243
BitDefenderThetaAI:Packer.B9374C4F21
CyrenW32/S-0a91bb6b!Eldorado
SymantecRansom.GlobeImpstr!g2
APEXMalicious
AvastWin32:Spora-B [Trj]
ClamAVWin.Ransomware.Globeimposter-6336186-0
KasperskyTrojan-Ransom.Win32.Agent.izk
AlibabaRansom:Win32/Spora.42bd9d13
NANO-AntivirusTrojan.Win32.Agent.eroxgo
ViRobotTrojan.Win32.Ransom.175537.A
AegisLabTrojan.Multi.Generic.4!c
TencentMalware.Win32.Gencirc.10b1a406
Ad-AwareTrojan.GenericKDZ.40027
TACHYONRansom/W32.Spora.175537
SophosML/PE-A + Troj/Emotet-CL
ComodoTrojWare.Win32.Crypt.AC@76tbx2
F-SecureHeuristic.HEUR/AGEN.1140035
DrWebTrojan.Encoder.13549
ZillyaTrojan.Agent.Win32.815036
McAfee-GW-EditionGenericRXDZ-ZK!2FE46A2C7324
EmsisoftTrojan.GenericKDZ.40027 (B)
JiangminTrojan.Scatter.ej
eGambitUnsafe.AI_Score_97%
AviraHEUR/AGEN.1140035
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Spora.B
SUPERAntiSpywareRansom.GlobeImposter/Variant
ZoneAlarmTrojan-Ransom.Win32.Agent.izk
GDataTrojan.GenericKDZ.40027
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Spora.C2073559
McAfeeGenericRXDZ-ZK!2FE46A2C7324
MAXmalware (ai score=87)
VBA32Hoax.Agent
MalwarebytesMalware.AI.4191140096
PandaTrj/GdSda.A
RisingRansom.Spora!8.E3EE (CLOUD)
YandexTrojan.GenAsa!7JgOtiomYRY
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.FUYC!tr
AVGWin32:Spora-B [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.8d2

How to remove Ransom:Win32/Spora.B?

Ransom:Win32/Spora.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment