Ransom

Generic.Ransom.AIT.Ouroboros.2.E3A1F312 (file analysis)

Malware Removal

The Generic.Ransom.AIT.Ouroboros.2.E3A1F312 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AIT.Ouroboros.2.E3A1F312 virus can do?

  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com

How to determine Generic.Ransom.AIT.Ouroboros.2.E3A1F312?


File Info:

crc32: 92F99498
md5: 31c08b624ef9772d30d9711ea9d55b9f
name: 31C08B624EF9772D30D9711EA9D55B9F.mlw
sha1: 1d61757b0087e7794f3ef86cd9ce4607fdce9c0d
sha256: 4d21c32382ee27af049e948e9140a8b3e8a0714b223d3c333b2d38b29d797924
sha512: b8cde5d877d95bef99b095582fbb84d0349426de1dafa0cb0651949e6ae0d4b075f5fd6fade4502b684b1a2b446986e09ffe362113198e96c45316a649b194c6
ssdeep: 24576:vAHnh+eWsN3skA4RV1Hom2KXMmHaTGOkrQ5:Sh+ZkldoPK8YaTA6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Generic.Ransom.AIT.Ouroboros.2.E3A1F312 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.MulDrop8.19757
CynetMalicious (score: 99)
CAT-QuickHealRansom.AutoIt.Genasom.ZZ
ALYacGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
CylanceUnsafe
AlibabaRansom:Win32/Crypmod.732e89ae
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.24ef97
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.NHN
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Crypmod.zhe
BitDefenderGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
NANO-AntivirusTrojan.Win32.Crypmod.fctmzy
MicroWorld-eScanGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
TencentWin32.Trojan.Crypmod.Ljtw
Ad-AwareGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
SophosMal/Generic-S
ComodoMalware@#24uwlrnwbrr48
BitDefenderThetaAI:Packer.C658345116
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
FireEyeGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
EmsisoftGeneric.Ransom.AIT.Ouroboros.2.E3A1F312 (B)
AviraHEUR/AGEN.1100014
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Occamy.C4D
ArcabitGeneric.Ransom.AIT.Ouroboros.2.E3A1F312
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.AIT.Ouroboros.2.E3A1F312 (2x)
AhnLab-V3Behavior_Ransom/Win32.Ransom.C4380485
McAfeeRDN/Ransom
MAXmalware (ai score=100)
PandaTrj/CI.A
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Ouroboros.A!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generic.Ransom.AIT.Ouroboros.2.E3A1F312?

Generic.Ransom.AIT.Ouroboros.2.E3A1F312 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment