Ransom

Should I remove “Generic.Ransom.AmnesiaE.61B57BC9”?

Malware Removal

The Generic.Ransom.AmnesiaE.61B57BC9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.61B57BC9 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.sfml-dev.org
pastebin.com

How to determine Generic.Ransom.AmnesiaE.61B57BC9?


File Info:

crc32: B775FFE6
md5: daa8723040a308ca5f19b83bc18b03f0
name: DAA8723040A308CA5F19B83BC18B03F0.mlw
sha1: 9bc7364d7bf1b13f7f5a93ab2c241e2befba698d
sha256: b6c2cb1fae44f3db051ea560eeec3d85b936644671b8ba40df6945895081b53e
sha512: 8c05b71141033b8fd922167d9ebf6d88e322ef1a5e7168ce40f5b1dd6bc4d4a08818fe2a66b3957740dd0f1f92eaecf3b41044b68a4698a01e45ec0422b28b40
ssdeep: 24576:RIiOd+fRSe6vPeM8HyUXTMs7BYiW8VUzrl3wcU:RI8fd6jPUwkBYz8yzrNwcU
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.61B57BC9 also known as:

BkavW32.FamVT.LimbozLA.Trojan
K7AntiVirusTrojan ( 005640be1 )
LionicTrojan.Win32.Imps.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29750
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S13760303
ALYacTrojan.Ransom.Ouroboros
CylanceUnsafe
SangforRansom.Win32.VoidCrypt.SK!MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/VoidCrypt.e06829d0
K7GWTrojan ( 005640be1 )
Cybereasonmalicious.040a30
CyrenW32/Ransom.MQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.E
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan-Ransom.Win32.Limbozar.vho
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.61B57BC9
NANO-AntivirusTrojan.Win32.Encoder.hklycb
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.61B57BC9
TencentWin32.Trojan.Filecoder.Wtxg
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.61B57BC9
SophosMal/Generic-R + Mal/Oboros-B
BitDefenderThetaGen:NN.ZexaF.34058.!uW@aiYxC5mi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.VOIDCRYPT.THFBCBO
McAfee-GW-EditionBehavesLike.Win32.Injector.dh
FireEyeGeneric.mg.daa8723040a308ca
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.61B57BC9 (B)
JiangminTrojan.DelShad.fq
WebrootW32.Ransom.Gen
AviraTR/FileCoder.rkuyq
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.3090F16
MicrosoftRansom:Win32/VoidCrypt.SK!MTB
ArcabitDeepScan:Generic.Ransom.AmnesiaE.61B57BC9
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.AmnesiaE.61B57BC9
AhnLab-V3Trojan/Win32.RL_FileCoder.R340210
McAfeeGenericRXMJ-AK!DAA8723040A3
MAXmalware (ai score=100)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.Ouroboros
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.VOIDCRYPT.THFBCBO
RisingRansom.Agent!1.C4E7 (CLASSIC)
YandexTrojan.Filecoder!tdLtCaadAPo
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Ouroboros.E!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Void.HwoCdh8A

How to remove Generic.Ransom.AmnesiaE.61B57BC9?

Generic.Ransom.AmnesiaE.61B57BC9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment