Ransom

What is “Generic.Ransom.Amnesia.48335000”?

Malware Removal

The Generic.Ransom.Amnesia.48335000 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.48335000 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Amnesia.48335000?


File Info:

crc32: 14C5CF8E
md5: bc0ad389512568c554c1154d6f10fda8
name: BC0AD389512568C554C1154D6F10FDA8.mlw
sha1: 4087acf963604161e2be05ce393e6662aa8c9574
sha256: 639a27c479f8cb7a5be7bd671a844f0cd1d2e7b8a514e6449a61177cba411232
sha512: fc7634553b5b868bcbccfb88d60dc5f41f2d6243862bd4a46b37f9f17e10703462db97e1a1487e708000e986535cd329a6f9be885af1d7cf8e0bb7b1dce2176c
ssdeep: 1536:xG6WeqBt3zxHZnYRd7X2HCo7QIeyF/0iNGhVx0b19:Q6WLVxHZ87X2P7QIeyF/0i8hVibH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.48335000 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f700b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.15054
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Amnesia
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.6488
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 004f700b1 )
Cybereasonmalicious.951256
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-6386031-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Amnesia.48335000
NANO-AntivirusTrojan.Win32.Filecoder.epnzwg
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.48335000
TencentWin32.Trojan.Filecoder.Pezi
Ad-AwareDeepScan:Generic.Ransom.Amnesia.48335000
SophosML/PE-A + Mal/DelpDldr-F
ComodoMalware@#imy8c46e2ylx
BitDefenderThetaAI:Packer.7410AABC1F
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
FireEyeGeneric.mg.bc0ad389512568c5
EmsisoftDeepScan:Generic.Ransom.Amnesia.48335000 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Genasom
ArcabitDeepScan:Generic.Ransom.Amnesia.D2E18898
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.48335000
AhnLab-V3Trojan/Win32.CryptXXX.R208829
Acronissuspicious
McAfeeArtemis!BC0AD3895125
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Kitoles
MalwarebytesMalware.Heuristic.1003
PandaTrj/RansomCrypt.D
TrendMicro-HouseCallMal_Purge
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.GenAsa!naaCZ9xMLiA
IkarusTrojan.Win32.Lnkhyd
FortinetW32/Filecoder.FS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Amnesia.HwsBjI8A

How to remove Generic.Ransom.Amnesia.48335000?

Generic.Ransom.Amnesia.48335000 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment