Categories: Ransom

What is “Generic.Ransom.AmnesiaE.8ED63650”?

The Generic.Ransom.AmnesiaE.8ED63650 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.8ED63650 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Anomalous file deletion behavior detected (10+)
  • Attempts to connect to a dead IP:Port (255 unique times)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to delete or modify volume shadow copies
  • Attempts to delete system state backup
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Appends a known LockBit ransomware file extension to files that have been encrypted
  • Creates a known LockBit ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.AmnesiaE.8ED63650?


File Info:

name: 3EE21DBAA37D0048E2E1.mlwpath: /opt/CAPEv2/storage/binaries/b02d57f1c4f7f233044a56fdc57c89b6cc3661479dccc3b4cfa1f6f9d20cd893crc32: 35033F73md5: 3ee21dbaa37d0048e2e174cb41a664d6sha1: f7799dc7530c3234dd2d5c11b74361b7ec1daefbsha256: b02d57f1c4f7f233044a56fdc57c89b6cc3661479dccc3b4cfa1f6f9d20cd893sha512: 7cfcc286522cc1d70f4f0d83e8a6e9ed27a7b94ead3f272a271ce1bf6708c91b0f19ddbf7cdebe44239c903142bd8f9b1949d17cbce0dd39e9491acb9744e947ssdeep: 1536:+uBQrT1eLBBdU/1GJj4UgvpedwwtVNUmrTF3MqqU+hV2xQie:+uBUwX0C4Vvs2wT+mr5MqqD/Fitype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T11D838C0A36A1E1B2C0A255F17B2D6ABB8D647C346354C0EB93905A14DE704D6BF39BCFsha3_384: 3ca25e320ab28f1e63f2bc1332248c046afb8c5c77d5117de7e132242a0b6139230513a1f542ba189958917a14a8d16cep_bytes: 558bec81ecc8020000568b352c114100timestamp: 2019-11-12 19:53:57

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.8ED63650 also known as:

Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.DelShad.4!c
Cynet Malicious (score: 100)
CAT-QuickHeal Ransom.LockBit.S12806943
McAfee Ransom-Lkbot!3EE21DBAA37D
Malwarebytes Ransom.LockBit
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056a69e1 )
BitDefender DeepScan:Generic.Ransom.AmnesiaE.8ED63650
K7GW Trojan ( 0056a69e1 )
Cybereason malicious.aa37d0
Cyren W32/Filecoder.AD.gen!Eldorado
Symantec Ransom.Cryptolocker
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Filecoder.Lockbit.B
APEX Malicious
Paloalto generic.ml
ClamAV Win.Ransomware.LockBitCombined-9375766-1
Kaspersky Trojan.Win32.DelShad.bqj
Alibaba Trojan:Win32/DelShad.7f67bcaf
NANO-Antivirus Trojan.Win32.Encoder.govsph
MicroWorld-eScan DeepScan:Generic.Ransom.AmnesiaE.8ED63650
Avast Win32:Malware-gen
Rising Ransom.LockBit!1.BFC2 (CLOUD)
Ad-Aware DeepScan:Generic.Ransom.AmnesiaE.8ED63650
Emsisoft DeepScan:Generic.Ransom.AmnesiaE.8ED63650 (B)
Comodo Malware@#22w79y2fp6hxr
F-Secure Trojan.TR/Crypt.ZPACK.Gen
DrWeb Trojan.Encoder.29662
Zillya Trojan.DelShad.Win32.220
TrendMicro Ransom.Win32.LOCKBIT.SMDS
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.mh
FireEye Generic.mg.3ee21dbaa37d0048
Sophos Mal/Generic-S
Ikarus Trojan-Ransom.FileCrypter
GData Win32.Trojan-Ransom.Filecoder.BO
Jiangmin Trojan.DelShad.kt
Webroot none
Avira TR/Crypt.ZPACK.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan/Generic.ASMalwS.2C7F27A
Arcabit DeepScan:Generic.Ransom.AmnesiaE.8ED63650
ZoneAlarm Trojan.Win32.DelShad.bqj
Microsoft Ransom:Win32/LockBit.A!MTB
AhnLab-V3 Malware/Win32.Generic.C3889599
Acronis suspicious
VBA32 BScope.Trojan.DelShad
ALYac Trojan.Ransom.Filecoder
Cylance Unsafe
TrendMicro-HouseCall Ransom.Win32.LOCKBIT.SMDS
Tencent Win32.Trojan.Delshad.Lplq
Yandex Trojan.DelShad!cnaqQddRx4Y
SentinelOne Static AI – Suspicious PE
MaxSecure Trojan.Malware.74134469.susgen
Fortinet W32/Filecoder.NXQ!tr.ransom
BitDefenderTheta Gen:NN.ZexaF.34606.fmW@a86CMrk
AVG Win32:Malware-gen
Panda Trj/GdSda.A
CrowdStrike win/malicious_confidence_100% (W)

How to remove Generic.Ransom.AmnesiaE.8ED63650?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “MSIL/TrojanDropper.Agent.BVT”?

The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Malware.AI.524217860 removal tips

The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Trojan:Win32/Koutodoor.F removal tips

The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

How to remove “Malware.AI.1412460714”?

The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Generic.Dacic.8952383F.A.5EC8C34B removal instruction

The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

1 day ago