Ransom

Generic.Ransom.AmnesiaE.F104C85B removal tips

Malware Removal

The Generic.Ransom.AmnesiaE.F104C85B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.AmnesiaE.F104C85B virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.my-ip.io
apps.identrust.com
crl.identrust.com

How to determine Generic.Ransom.AmnesiaE.F104C85B?


File Info:

crc32: DE44B0F4
md5: 2659af8deab12171b7e8c51913f15469
name: 2659AF8DEAB12171B7E8C51913F15469.mlw
sha1: 08ec17dc46600378518e5049baad90554993ced8
sha256: 8bea5d61c39086cde781162fe528897777533a7251b774d5a80abe7fe8723f9d
sha512: f4132a5960aea202d7233758394685f842eb34eb776e0c306a5cc7d7cd5339adea5769f3db5ca3dd063cb154d0ad95290d91bdf96146219eefcb2243a74b6186
ssdeep: 24576:LSUd4wd1XQ/EFd6oQ7dWWCjm1bmitsxq6OYAw3A8ckOXJATVVMrzpYLnUMDIE:+UmwcIJjtAsw6F9xO03MrdY7UMDIE
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.AmnesiaE.F104C85B also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34144
MicroWorld-eScanDeepScan:Generic.Ransom.AmnesiaE.F104C85B
ALYacDeepScan:Generic.Ransom.AmnesiaE.F104C85B
SangforTrojan.Win32.Save.a
Cybereasonmalicious.deab12
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.G
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Vipasana-9783618-1
KasperskyHEUR:Trojan.Win32.Stosek.gen
BitDefenderDeepScan:Generic.Ransom.AmnesiaE.F104C85B
NANO-AntivirusTrojan.Win32.Stosek.ivcvkt
Ad-AwareDeepScan:Generic.Ransom.AmnesiaE.F104C85B
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1139736
BitDefenderThetaGen:NN.ZexaF.34104.rvW@aiJsNali
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.VOIDCRYPT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftDeepScan:Generic.Ransom.AmnesiaE.F104C85B (B)
JiangminTrojan.Generic.gtxwb
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.1B2
ArcabitDeepScan:Generic.Ransom.AmnesiaE.F104C85B
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.AmnesiaE.F104C85B
TACHYONRansom/W32.Spyro.1342464
AhnLab-V3Ransomware/Win.VOIDCRYPT.C4454770
McAfeeGenericRXON-UG!2659AF8DEAB1
MAXmalware (ai score=89)
VBA32Trojan.Stosek
MalwarebytesRansom.VoidCrypt
TrendMicro-HouseCallRansom.Win32.VOIDCRYPT.SM
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ouroboros.G!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.AmnesiaE.F104C85B?

Generic.Ransom.AmnesiaE.F104C85B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment