Ransom

Generic.Ransom.Amnesia.F90E2F4D removal

Malware Removal

The Generic.Ransom.Amnesia.F90E2F4D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.F90E2F4D virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

iplogger.co
iplogger.org
ocsp.comodoca.com
ocsp.sectigo.com
crl.usertrust.com
ocsp.usertrust.com

How to determine Generic.Ransom.Amnesia.F90E2F4D?


File Info:

crc32: 9695B87E
md5: b9e3ddf0d216c1aa58f0a1e6f4e178ba
name: B9E3DDF0D216C1AA58F0A1E6F4E178BA.mlw
sha1: ef68a31f13dca20bab55b177ae39af6154c45754
sha256: b86e3eccfc9da0a5842c13d96debd9b9fea89eb03d763817b8bd4f21574d7a3a
sha512: b03c93354b681b0af66908a1d0b08975781c4ed1f48fa7830d826e583ecc1af5a8a5d87cd80bf770107669a8ea774818e2fc1f8696a0ac5f11d6be7f294e413b
ssdeep: 24576:nGVpWx7VWt5fPYEa5DmLn2O32alH9JmSkxSoiiun361GEw1xU/Cube+IP9tY4GFy:ofPYEYwrldqkoKT1x1lv9C4BnEo
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.F90E2F4D also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f6e981 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11464
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Sigmal.S3104595
ALYacTrojan.Ransom.Scarab
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Kitoles.2afe4e46
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.0d216c
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6965729-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderDeepScan:Generic.Ransom.Amnesia.F90E2F4D
NANO-AntivirusTrojan.Win32.Encoder.felmay
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.F90E2F4D
TencentWin32.Trojan.Filecoder.Pjdj
Ad-AwareDeepScan:Generic.Ransom.Amnesia.F90E2F4D
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.E7605DED1F
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Pluto.tc
FireEyeGeneric.mg.b9e3ddf0d216c1aa
EmsisoftDeepScan:Generic.Ransom.Amnesia.F90E2F4D (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.bjim
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.26B1398
MicrosoftRansom:Win32/Kitoles.A
ArcabitDeepScan:Generic.Ransom.Amnesia.F90E2F4D
GDataDeepScan:Generic.Ransom.Amnesia.F90E2F4D
AhnLab-V3Trojan/Win32.Ransom.R256667
McAfeeGenericRXGB-WP!B9E3DDF0D216
MAXmalware (ai score=99)
VBA32BScope.Trojan.Encoder
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
RisingRansom.Kitoles!1.BACD (CLASSIC)
YandexTrojan.GenAsa!am1hUDPGDJQ
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Amnesia.HgAASRoA

How to remove Generic.Ransom.Amnesia.F90E2F4D?

Generic.Ransom.Amnesia.F90E2F4D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment