Ransom

Generic.Ransom.AmnesiaE.1F344342 removal guide

Malware Removal

The Generic.Ransom.AmnesiaE.1F344342 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.1F344342 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.my-ip.io
apps.identrust.com

How to determine Generic.Ransom.AmnesiaE.1F344342?


File Info:

crc32: 82C704FA
md5: 41a1de72cf900c3b706e8ca988458e87
name: 41A1DE72CF900C3B706E8CA988458E87.mlw
sha1: 99b030199867c286888ca4bfb1a785fd46390417
sha256: 49fb7f5369ea89d11972eec3c269e6ab7451368ab6ec2ba4d8213a30fa40f021
sha512: 9cec1089516df3e4fdeb011cc13889f61ee3cf17508938ed57374903b52d9b942dba176f64eae0c0ace451f81a98c8e583c5276c043eab96f729b442a9ff93f2
ssdeep: 24576:slUQAwd1Xo/EFdyoQztWryzKDr2y9cxq6eIAFnA8Mn+I8Qc8dJL0iUIDYnUMVSj:EUjw0AszLgcw6a9K+J8JL0Xy8UMVSj
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.1F344342 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.AmnesiaE.1F344342
SangforTrojan.Win32.Save.a
Cybereasonmalicious.2cf900
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.1F344342
NANO-AntivirusTrojan.Win32.Stosek.ivcvkt
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.1F344342
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.1F344342
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34722.rvW@aSQUWCdi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.VOIDCRYPT.SM
McAfee-GW-EditionGenericRXON-UG!41A1DE72CF90
FireEyeDeepScan:Generic.Ransom.AmnesiaE.1F344342
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.1F344342 (B)
JiangminTrojan.Generic.gtxwb
AviraHEUR/AGEN.1139736
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitDeepScan:Generic.Ransom.AmnesiaE.1F344342
GDataDeepScan:Generic.Ransom.AmnesiaE.1F344342
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
McAfeeGenericRXON-UG!41A1DE72CF90
MAXmalware (ai score=83)
VBA32Trojan.Stosek
MalwarebytesRansom.Ouroboros
TrendMicro-HouseCallRansom.Win32.VOIDCRYPT.SM
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ouroboros.G!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.1F344342?

Generic.Ransom.AmnesiaE.1F344342 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment