Ransom

Generic.Ransom.Amnesia.B291C05B malicious file

Malware Removal

The Generic.Ransom.Amnesia.B291C05B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.B291C05B virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Amnesia.B291C05B?


File Info:

crc32: 8DD6B9D5
md5: d4773bab29d8f4234eae1e33ab9a965f
name: D4773BAB29D8F4234EAE1E33AB9A965F.mlw
sha1: 595e0a9cf452a0078b5a2b800fcecc037383f467
sha256: 31bb9cac3d4f3287d550dc726d4b07ef5e34ca288c581937b4051c7b50899b55
sha512: aafb311fc3aa24e7326e3b1ef534b98d1e8bb847e5992d0c174b5b38470b51711c7ffd70ec90107ef112dc7db4a5dc9b6218d33b28c22a2f933aa2bfa9b4dbca
ssdeep: 3072:GBp4xwPY4yZpfySOttQz/D6hsZWrVyRp+ljpPk:GBp46Y4aVG4DlZWZyqjS
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.B291C05B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.B291C05B
FireEyeGeneric.mg.d4773bab29d8f423
McAfeeRansom-Amnesia!D4773BAB29D8
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderDeepScan:Generic.Ransom.Amnesia.B291C05B
Cybereasonmalicious.b29d8f
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.epnzwg
AvastWin32:Dh-A [Heur]
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazornHTwpM8zxrbqenbZ0Qt5)
Ad-AwareDeepScan:Generic.Ransom.Amnesia.B291C05B
SophosML/PE-A + Mal/DelpDldr-F
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureDropper.DR/Delphi.Gen7
DrWebTrojan.Encoder.15054
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Sytro.ch
EmsisoftDeepScan:Generic.Ransom.Amnesia.B291C05B (B)
IkarusTrojan.Win32.Lnkhyd
JiangminTrojan.Generic.bswxs
AviraDR/Delphi.Gen7
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Amnesia.VSB!MTB
ArcabitDeepScan:Generic.Ransom.Amnesia.B291C05B
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.B291C05B
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4294864
Acronissuspicious
BitDefenderThetaAI:Packer.2F0520BD1F
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Kitoles
MalwarebytesMalware.AI.3932874182
ESET-NOD32a variant of Win32/Filecoder.FS
TrendMicro-HouseCallMal_Purge
YandexTrojan.GenAsa!Dy18OPPLTiI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.FS!tr
AVGWin32:Dh-A [Heur]
PandaTrj/RansomCrypt.D
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM05.1.A270.Malware.Gen

How to remove Generic.Ransom.Amnesia.B291C05B?

Generic.Ransom.Amnesia.B291C05B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment