Ransom

Generic.Ransom.Amnesia.6CC281E3 removal instruction

Malware Removal

The Generic.Ransom.Amnesia.6CC281E3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.6CC281E3 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

iplogger.co
iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com
ocsp.sectigo.com

How to determine Generic.Ransom.Amnesia.6CC281E3?


File Info:

crc32: 33E044FA
md5: a925ff5ea8de65176a5060b4f1daf76f
name: A925FF5EA8DE65176A5060B4F1DAF76F.mlw
sha1: 6d5cfbcf4c2425edb45db7e8611d24689f8554f6
sha256: da36c27048a811df183c8186df8d02c4fa12c00d5cd84801f870dd58d10cf69b
sha512: 28983db81aa67a4835fc26533c1684d646eb9b57c6e3a620f38bca14276fa8a7a4cb8c2ab574af0c00b4d04cd40f6a840cbfca3d941e415b4b0a12724ce0d2a3
ssdeep: 6144:S1NfVst953URUCE8WORdmz5mnHWXCkjHPut8upaL3Vo:SBst9d7CE8WOqMHWP72Wup03V
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.6CC281E3 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f6e981 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26376
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Scarab
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.8120
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Higuniel.5c3978a6
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.ea8de6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Deepscan-6975721-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderDeepScan:Generic.Ransom.Amnesia.6CC281E3
NANO-AntivirusTrojan.Win32.Filecoder.fhmpgm
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.6CC281E3
TencentWin32.Trojan.Filecoder.Llqr
Ad-AwareDeepScan:Generic.Ransom.Amnesia.6CC281E3
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.DC5FD0F51E
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dh
FireEyeGeneric.mg.a925ff5ea8de6517
EmsisoftDeepScan:Generic.Ransom.Amnesia.6CC281E3 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117085
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Higuniel.A
GDataDeepScan:Generic.Ransom.Amnesia.6CC281E3
AhnLab-V3Malware/Win32.Purge.C2596671
Acronissuspicious
McAfeeGenericRXGB-WP!A925FF5EA8DE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
RisingRansom.Scarab!1.BACD (CLASSIC)
YandexTrojan.GenAsa!UDTQ20lr1Po
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Amnesia.6CC281E3?

Generic.Ransom.Amnesia.6CC281E3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment