Ransom

About “Generic.Ransom.AmnesiaE.AEB692B8 (B)” infection

Malware Removal

The Generic.Ransom.AmnesiaE.AEB692B8 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.AEB692B8 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to delete system state backup
  • Writes a potential ransom message to disk
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Disables Windows firewall
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.AmnesiaE.AEB692B8 (B)?


File Info:

name: E3CF8BA114722D1EB5A7.mlw
path: /opt/CAPEv2/storage/binaries/a6607e166a842e76948428479b57cf690db0c2f038cb6d060381f8eb222a2493
crc32: 54D06AED
md5: e3cf8ba114722d1eb5a775215d1beee9
sha1: 820d0a0284f4ae4cc12d88211209a121ef516ac8
sha256: a6607e166a842e76948428479b57cf690db0c2f038cb6d060381f8eb222a2493
sha512: 62fa04c92bde2522ce52ad79632e5f58ee240e502dfe18cfccd2eb5c42b29c9d4971c626ce72a149290797ddc0d8e3a0882d92d3c0b0def51d54114e50d2d8b2
ssdeep: 98304:Bhkl7LNYHqAXPfVmVVzfUx0oyVYUFkApH:YFLNsVWVzXNGUr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11BF502217A03D0B2D5A100F08A79BB7B5A6EAE351B7046C7F3D41F3D59311C29A37B6A
sha3_384: 78e12f324fe0111b17ee617a45803f334d152caa92d57aa68f8d4111f1ca223b896ab36c821b42c4b8f13077a4b4750c
ep_bytes: e8810f0000e974feffffcccccccc5756
timestamp: 2021-12-11 02:15:02

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.AEB692B8 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.AEB692B8
McAfeeGenericRXAA-AA!E3CF8BA11472
CylanceUnsafe
SangforRansom.Win32.Generic.ky
K7AntiVirusTrojan ( 005789501 )
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.AEB692B8
K7GWTrojan ( 005789501 )
Cybereasonmalicious.114722
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
Paloaltogeneric.ml
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/Taleb.73978ac7
TencentMalware.Win32.Gencirc.11df12b0
SophosMal/Generic-S
DrWebTrojan.Encoder.34668
ZillyaTrojan.Filecoder.Win32.21348
TrendMicroRansom_Taleb.R002C0DB322
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
FireEyeDeepScan:Generic.Ransom.AmnesiaE.AEB692B8
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.AEB692B8 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hedwi
AviraHEUR/AGEN.1145567
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34E7B12
MicrosoftRansom:Win32/Taleb.PAA!MTB
ViRobotTrojan.Win32.Z.Ouroboros.3332495
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.AmnesiaE.AEB692B8
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
VBA32Trojan.Encoder
ALYacDeepScan:Generic.Ransom.AmnesiaE.AEB692B8
MalwarebytesRansom.FileCryptor
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Taleb.R002C0DB322
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.Filecoder!RY5Lkw4Cno4
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ouroboros.G!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34182.lxZ@aaNvO8ai
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.AEB692B8 (B)?

Generic.Ransom.AmnesiaE.AEB692B8 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment