Ransom Trojan

Trojan.Ransom.Spora removal instruction

Malware Removal

The Trojan.Ransom.Spora is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Spora virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Spora?


File Info:

crc32: 5756A6FA
md5: 898d08d90bec29edae2b345c341dd860
name: 898D08D90BEC29EDAE2B345C341DD860.mlw
sha1: 279d53b75b84c86ca97fe448225d7993fa773142
sha256: 99b837320b7fd776a85b3b605666319ddbf8a3a96ada437953688be3418f92ae
sha512: 647cdc57ea9dc2a71d1fcb367b95add5a4fdad8c250b53f00601aabf445b5f92a129c7ca44cc5206d18ef03f79a245e4ec6fd1277224b98ed75e40d74ea1414b
ssdeep: 768:aVmw8uWL4xe4a3BIITwJ1J5j4UYZEUe1gyD1nPPDtYBMwk+e+31JDB8uWL4xe4:aAwefh+1xYZEUe1r1nztA73he
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Spora also known as:

BkavW32.Common.34F0070D
K7AntiVirusTrojan ( 0051918c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10103
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A4
ALYacTrojan.Ransom.Spora
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1083482
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Kryptik.37d04ceb
K7GWTrojan ( 005054af1 )
Cybereasonmalicious.90bec2
BaiduWin32.Trojan.Kryptik.bjm
CyrenW32/S-c8e0bb6a!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FOJY
APEXMalicious
AvastWin32:Filecoder-BD [Trj]
ClamAVWin.Ransomware.Spora-6978815-0
KasperskyHEUR:Trojan-Ransom.Win32.Spora.pef
BitDefenderGen:Variant.Agiala.25
NANO-AntivirusTrojan.Win32.Spora.elobkh
MicroWorld-eScanGen:Variant.Agiala.25
TencentMalware.Win32.Gencirc.11492715
Ad-AwareGen:Variant.Agiala.25
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34628.eqW@aWBgLnc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM3B
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.898d08d90bec29ed
EmsisoftTrojan-Ransom.Spora (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.auubn
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1105007
eGambitUnsafe.AI_Score_59%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Spora.A
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Agiala.25
AhnLab-V3Trojan/Win32.Spora.R195423
McAfeeRansom-Spora!898D08D90BEC
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Spora
MalwarebytesRansom.Spora
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SM3B
RisingRansom.Spora!8.E3EE (KTSE)
YandexTrojan.GenAsa!B54Q8Wb3aME
IkarusTrojan-Ransom.Spora
FortinetW32/GenKryptik.GSOD!tr
AVGWin32:Filecoder-BD [Trj]
Qihoo-360Win32/Ransom.Filecoder.HxQBGncA

How to remove Trojan.Ransom.Spora?

Trojan.Ransom.Spora removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment