Ransom

Should I remove “Generic.Ransom.Amnesia.FF8EDA42”?

Malware Removal

The Generic.Ransom.Amnesia.FF8EDA42 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.FF8EDA42 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Clears Windows events or logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Amnesia.FF8EDA42?


File Info:

crc32: DE82A1B5
md5: 0da14b37d55c7542bd4a567b01e05c7f
name: 0DA14B37D55C7542BD4A567B01E05C7F.mlw
sha1: d583285237e706907cf6c69438518ba70410017b
sha256: b5a9081f4a17be5918d5e3f93ce8c7cc6ae72e198b92067c4dcaa797d25e50ff
sha512: 2801459ecca288e626f335871ad3ed6a395ba71ff1c5947e6def2e349073f04c512073ecc8bf0e42aad6270a312b695ecf81e54f1b625478d4bea2f7893f9fee
ssdeep: 3072:pYpoi+QvG5EiigZBFuXLWkB+k62aW62amug62aW62amu4OA62aW62amu4OYuIsw:+poq+Ei3u7Ww+VB
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.FF8EDA42 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWIN.WORM.Virus
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.FF8EDA42
FireEyeGeneric.mg.0da14b37d55c7542
McAfeeRansom-Amnesia!0DA14B37D55C
CylanceUnsafe
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
SangforTrojan.Win32.Save.a
BitDefenderDeepScan:Generic.Ransom.Amnesia.FF8EDA42
Cybereasonmalicious.7d55c7
BitDefenderThetaAI:Packer.2B0F0C421F
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Dh-A [Heur]
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.epnvsc
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrQYVumRzE5lAwJ+ODwtjqL)
Ad-AwareDeepScan:Generic.Ransom.Amnesia.FF8EDA42
EmsisoftDeepScan:Generic.Ransom.Amnesia.FF8EDA42 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureDropper.DR/Delphi.Gen7
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Sytro.ch
SophosML/PE-A + Mal/DelpDldr-F
IkarusTrojan.Win32.Lnkhyd
JiangminTrojan.Generic.bmcfs
AviraDR/Delphi.Gen7
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftRansom:Win32/Amnesia.VSB!MTB
ArcabitDeepScan:Generic.Ransom.Amnesia.FF8EDA42
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.FF8EDA42
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4294864
Acronissuspicious
VBA32BScope.TrojanRansom.Kitoles
ALYacDeepScan:Generic.Ransom.Amnesia.FF8EDA42
MAXmalware (ai score=84)
MalwarebytesMalware.Heuristic.1006
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.FS
TrendMicro-HouseCallMal_Purge
YandexTrojan.GenAsa!Dy18OPPLTiI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.FS!tr
AVGWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM05.1.A270.Malware.Gen

How to remove Generic.Ransom.Amnesia.FF8EDA42?

Generic.Ransom.Amnesia.FF8EDA42 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment