Ransom

Generic.Ransom.AmnesiaE.5F1FDA99 removal tips

Malware Removal

The Generic.Ransom.AmnesiaE.5F1FDA99 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.5F1FDA99 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to delete system state backup
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • CAPE detected the Spyro malware family
  • Creates a copy of itself
  • Disables Windows firewall
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.AmnesiaE.5F1FDA99?


File Info:

name: 4C86E703D15D1D810BD6.mlw
path: /opt/CAPEv2/storage/binaries/a06cac7cb634df7549607f528b6ec3194190f0eeae0744db18cf1a5b0afbbcaa
crc32: DEF4D73B
md5: 4c86e703d15d1d810bd62b01f4f6aaa4
sha1: 41fd2b4faa8b920561d3fa9b95f8430905f60fa4
sha256: a06cac7cb634df7549607f528b6ec3194190f0eeae0744db18cf1a5b0afbbcaa
sha512: e53aecdb1771153e6c48ff33b14f641948888c69a2744e01cf5eb1244ca1ade16da94cfebf50df3b9e55c51f93d295dfb09777c7bdcc5b9943e5b4a6f5a909cc
ssdeep: 98304:9UBRRln3xO0/AGwqE1rjFVmIpICnWTMZ/rzpw27VWMszzLCG1:YRl//wqEpjFVJ3KMZ/rzO27IbPv
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C5361251BA43C0B2D49101F04D7CAB7B5A2CAF291B748AD7E3C85E3D99301D25A37B9B
sha3_384: 1900d74fd7ad20b30b7e836a34f74d40b1b8819d6b9454a52d9866d552a63374db843bc88030cc095405c3375953bdec
ep_bytes: e8810f0000e974feffffcccccccc5756
timestamp: 2021-05-09 22:28:48

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.5F1FDA99 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34144
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
FireEyeGeneric.mg.4c86e703d15d1d81
McAfeeGenericRXON-UG!4C86E703D15D
K7AntiVirusTrojan ( 005785c51 )
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
K7GWTrojan ( 005785c51 )
BitDefenderThetaGen:NN.ZexaF.34182.@xZ@aaWhe3gi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Stosek.ivcvkt
RisingRansom.HydraCrypt!8.864F (RDMK:cmRtazoaRozDt6itnl+DCoTmSHGG)
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99 (B)
IkarusTrojan-Ransom.Ouroboros
GDataDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
JiangminTrojan.Generic.gtxwb
AviraHEUR/AGEN.1223866
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASCommon.1B2
ArcabitDeepScan:Generic.Ransom.AmnesiaE.5F1FDA99
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win32/HydraCrypt.PAA!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
VBA32Trojan.Stosek
MalwarebytesRansom.VoidCrypt
PandaTrj/Genetic.gen
APEXMalicious
TencentMalware.Win32.Gencirc.11d67f40
YandexTrojan.Filecoder!UwxmFocxHgo
SentinelOneStatic AI – Malicious PE
FortinetW32/Ouroboros.G!tr.ransom
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.5F1FDA99?

Generic.Ransom.AmnesiaE.5F1FDA99 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment