Ransom

Generic.Ransom.AmnesiaE.5F1FDA99 (B) removal guide

Malware Removal

The Generic.Ransom.AmnesiaE.5F1FDA99 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.5F1FDA99 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to delete system state backup
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • CAPE detected the Spyro malware family
  • Creates a copy of itself
  • Disables Windows firewall
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.AmnesiaE.5F1FDA99 (B)?


File Info:

name: 31B4ED603DDDCF2C3706.mlw
path: /opt/CAPEv2/storage/binaries/9c19656e3bb59553ddfa3430920a0f1e8bacd9132962462c1ed896c1f6f5f87c
crc32: 6CAC9B4A
md5: 31b4ed603dddcf2c3706711461d812ed
sha1: c4dae0843d4aeedf7a6afa560fd9f1100984579d
sha256: 9c19656e3bb59553ddfa3430920a0f1e8bacd9132962462c1ed896c1f6f5f87c
sha512: 66175d163e33e4f1e3267bcbf4314c925633e8fb00535f464cb44800b88a817758098f0af9b3c940ab542efc0f556c987c3b2856bbbd25b47d286e075b131802
ssdeep: 98304:9UBRRln3xO0/A3CRLdqXxgaf8sEd+9tf/SWOW:YRl/0Cjyn0Vd4MWOW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10A1612517D43C0B2E58100F0897DAB7B8A2CAF2917708AD7E3C86E7D59305D1AA3779B
sha3_384: 5ed910512aec07f79e6340d6854c33b39aefa875aa82cbda4b9ad2754b8d41d17d3193a980c394c81b23e457dcd2a347
ep_bytes: e8810f0000e974feffffcccccccc5756
timestamp: 2021-05-09 22:28:48

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.5F1FDA99 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34144
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
FireEyeGeneric.mg.31b4ed603dddcf2c
ALYacDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005785c51 )
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
K7GWTrojan ( 005785c51 )
BitDefenderThetaGen:NN.ZexaF.34212.8xZ@aaWhe3gi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
APEXMalicious
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Stosek.ivcvkt
RisingRansom.HydraCrypt!8.864F (TFE:5:09GFi9wmOsK)
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
JiangminTrojan.Generic.gtxwb
AviraHEUR/AGEN.1223866
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASCommon.1B2
MicrosoftRansom:Win32/HydraCrypt.PAA!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
McAfeeGenericRXON-UG!31B4ED603DDD
VBA32Trojan.Stosek
MalwarebytesRansom.VoidCrypt
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.11d67f40
YandexTrojan.Filecoder!UwxmFocxHgo
IkarusTrojan-Ransom.Ouroboros
FortinetW32/Ouroboros.G!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.03dddc
AvastWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.5F1FDA99 (B)?

Generic.Ransom.AmnesiaE.5F1FDA99 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment