Ransom

Generic.Ransom.AmnesiaE.100233CC removal guide

Malware Removal

The Generic.Ransom.AmnesiaE.100233CC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.100233CC virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.my-ip.io
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org

How to determine Generic.Ransom.AmnesiaE.100233CC?


File Info:

crc32: BC7E8124
md5: 4649d6e5dc853f036bc0926a8c73aa6f
name: 4649D6E5DC853F036BC0926A8C73AA6F.mlw
sha1: 1f9f15974886c62e6beaee3fa1782e67c4df9776
sha256: b8e12c0593baa490ffaa42022d62739a908059e61e73d010f26d344bebb64191
sha512: f55001c118691b5a6a46d1b5535d231289a4b6b56449276fa30a2e3ecd1e7f9c024ff8019657ec0a79716e6be6ea970e30c27bfcbfbf4d4d9648ccd21d79f0fc
ssdeep: 24576:BGUpQwd1X4/EFdioQDNW7CDqDqWCN9xq6u6A1XO88I8ttgcsrQhVMumnUMaf6:IUKwkQcDUA9w6wHx8dCQhiuaUMaf6
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.100233CC also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.AmnesiaE.100233CC
ZillyaTrojan.Filecoder.Win32.19469
SangforTrojan.Win32.Save.a
Cybereasonmalicious.5dc853
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan.Win32.Stosek.gen
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.100233CC
NANO-AntivirusTrojan.Win32.Stosek.ivcvkt
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.100233CC
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.100233CC
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34738.rvW@aGAJBphi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.VOIDCRYPT.SM
McAfee-GW-EditionGenericRXON-UG!4649D6E5DC85
FireEyeDeepScan:Generic.Ransom.AmnesiaE.100233CC
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.100233CC (B)
JiangminTrojan.Generic.gtxwb
AviraHEUR/AGEN.1139736
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.1B2
MicrosoftRansom:Win32/Filecoder!ml
ArcabitDeepScan:Generic.Ransom.AmnesiaE.D18789CC
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.AmnesiaE.100233CC
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
McAfeeGenericRXON-UG!4649D6E5DC85
MAXmalware (ai score=88)
VBA32Trojan.Stosek
MalwarebytesRansom.Ouroboros
TrendMicro-HouseCallRansom.Win32.VOIDCRYPT.SM
YandexTrojan.Filecoder!BlA8CMjXWYc
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ouroboros.G!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.100233CC?

Generic.Ransom.AmnesiaE.100233CC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment