Ransom

Generic.Ransom.Amnesia.DBE47516 removal tips

Malware Removal

The Generic.Ransom.Amnesia.DBE47516 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.DBE47516 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.Ransom.Amnesia.DBE47516?


File Info:

crc32: 17EC5A99
md5: b6e1d0faa1c64efcb15308fb6b86b96a
name: B6E1D0FAA1C64EFCB15308FB6B86B96A.mlw
sha1: 1899cda284b600b7b4649fddee6848c785928801
sha256: 111214fb1f939362bcfc501b7fecbe946eefff8b85223e0fa02b49a85037037a
sha512: ed5fc3a2fe0dc7a1a4e4c32e1616df1f010ad55c0291f760916907344333016dd5aaa61d52d6171af52794fe4c8cb639ead22b51d6b1a3e9adeb28bfce01dc4f
ssdeep: 6144:euakY++95PhxWQFglV4kUcUgtPRLr/45QKnO/FB:ebp5PPWQUVvlRHcnoF
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.DBE47516 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26375
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Amnesia.DBE47516
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Pulobe.aa4204cb
Cybereasonmalicious.aa1c64
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Deepscan-6975721-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Amnesia.DBE47516
NANO-AntivirusTrojan.Win32.Encoder.hmgtyq
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.DBE47516
Ad-AwareDeepScan:Generic.Ransom.Amnesia.DBE47516
SophosML/PE-A
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.F94884211F
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
FireEyeGeneric.mg.b6e1d0faa1c64efc
EmsisoftDeepScan:Generic.Ransom.Amnesia.DBE47516 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Pulobe.RB!MSR
ArcabitDeepScan:Generic.Ransom.Amnesia.DBEDB99C
GDataDeepScan:Generic.Ransom.Amnesia.DBE47516
AhnLab-V3Trojan/Win32.Ransom.R338400
Acronissuspicious
McAfeeRansom-Scarab!B6E1D0FAA1C6
MAXmalware (ai score=80)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Scarab
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
RisingRansom.Kitoles!1.BACD (CLOUD)
YandexTrojan.GenAsa!bXAtAcuJUJk
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Msht.GJ!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Generic.Ransom.Amnesia.DBE47516?

Generic.Ransom.Amnesia.DBE47516 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment