Ransom

Generic.Ransom.AmnesiaE.3AA0F647 malicious file

Malware Removal

The Generic.Ransom.AmnesiaE.3AA0F647 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.3AA0F647 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Exhibits possible ransomware file modification behavior
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.sfml-dev.org
pastebin.com

How to determine Generic.Ransom.AmnesiaE.3AA0F647?


File Info:

crc32: C1CE0DAC
md5: 99263717a48b1ad13dbe3b2c26b4e44b
name: 99263717A48B1AD13DBE3B2C26B4E44B.mlw
sha1: d35bad868a23c2e48c5d5879d63cfb23dc40f5f1
sha256: 52b2a6cdfdb1cea413234b249f24c8b5b68b48c1389a513250f7588bc64596cd
sha512: f6cee3a94237948bf43d2dbcc22bca7e2e3703b52b55c00ed1c8d06bd7d6b778c37392368a31287f90b6474ca2a4aaa378017fe0d03a4f3439a373155b2fe252
ssdeep: 24576:VIZO9UbRSe6P4Jw8nSUDSM9m3Tx8isSlE:VItbd6fPUZk3V8TSi
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.3AA0F647 also known as:

BkavW32.FamVT.LimbozLA.Trojan
K7AntiVirusTrojan ( 005640be1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29750
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S13760303
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.16113
SangforTrojan.Win32.VoidCrypt.usrg
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/VoidCrypt.ffd71598
K7GWTrojan ( 005640be1 )
Cybereasonmalicious.7a48b1
CyrenW32/Ransom.MQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.E
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Deepscan-9739386-0
KasperskyHEUR:Trojan-Ransom.Win32.Limbozar.vho
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.3AA0F647
NANO-AntivirusTrojan.Win32.Encoder.hklycb
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.3AA0F647
TencentWin32.Trojan.Filecoder.Hssc
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.3AA0F647
SophosMal/Generic-S + Mal/Oboros-B
ComodoMalware@#1t38lauvfknaf
BitDefenderThetaGen:NN.ZexaF.34058.!uW@aiA!dmhi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.VOIDCRYPT.SMTH
McAfee-GW-EditionBehavesLike.Win32.Injector.dh
FireEyeGeneric.mg.99263717a48b1ad1
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.3AA0F647 (B)
JiangminTrojan.DelShad.fq
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1135982
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.30B4CC2
MicrosoftRansom:Win32/VoidCrypt.SK!MTB
ArcabitDeepScan:Generic.Ransom.AmnesiaE.3AA0F647
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.AmnesiaE.3AA0F647
AhnLab-V3Trojan/Win32.RL_FileCoder.R340210
McAfeeGenericRXMJ-AK!99263717A48B
MAXmalware (ai score=100)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.Ouroboros
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.VOIDCRYPT.SMTH
RisingRansom.Agent!1.C4E7 (CLASSIC)
YandexTrojan.Filecoder!MUHbWDGte/s
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Ouroboros.E!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Void.HwoC2VAA

How to remove Generic.Ransom.AmnesiaE.3AA0F647?

Generic.Ransom.AmnesiaE.3AA0F647 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment