Ransom

What is “Generic.Ransom.BTCWare.E220ACC5”?

Malware Removal

The Generic.Ransom.BTCWare.E220ACC5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.BTCWare.E220ACC5 virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Generic.Ransom.BTCWare.E220ACC5?


File Info:

crc32: E3C1D325
md5: c6e224c8442c1566edfd80755553b066
name: C6E224C8442C1566EDFD80755553B066.mlw
sha1: 67f6d9255dbd5938c69353fcf3e4f4f9569a2dfa
sha256: 741950e9be430267efff601fca1a7c21b65b904658fa46f9e618ea50787faaac
sha512: 7232e5b304249944c9825a51b038dfbef84a9ff61bf8d5857607738a2c760860b66bd82122a7f840b70ad042c220480748ef29fb8647b7e778703ca6909e74aa
ssdeep: 3072:U8xXG8B2El27VxiKxjF+xLtAN1vxgyRuY:UA23xJjF+xLCvj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.BTCWare.E220ACC5 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050b0f71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.12233
CynetMalicious (score: 100)
CAT-QuickHealRansom.Betisrypt.S1080239
ALYacDeepScan:Generic.Ransom.BTCWare.E220ACC5
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5485
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Alibabavirus:Win32/InfectPE.ali2000007
K7GWTrojan ( 0050b0f71 )
Cybereasonmalicious.8442c1
SymantecRansom.Locky!gm
ESET-NOD32a variant of Win32/Filecoder.BTCware.E
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.BTCWare-6329927-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.BTCWare.E220ACC5
NANO-AntivirusTrojan.Win32.Encoder.ezjazs
MicroWorld-eScanDeepScan:Generic.Ransom.BTCWare.E220ACC5
TencentTrojan.Win32.BTCWare.a
Ad-AwareDeepScan:Generic.Ransom.BTCWare.E220ACC5
SophosMal/Generic-R + Troj/Btcware-A
ComodoMalware@#5u3elfyw6fev
BitDefenderThetaAI:Packer.7E1E66D71E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_BTCWARE.F117F2
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.c6e224c8442c1566
EmsisoftDeepScan:Generic.Ransom.BTCWare.E220ACC5 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bafvv
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122952
Antiy-AVLTrojan/Generic.ASMalwS.20E1AA8
MicrosoftRansom:Win32/Betisrypt!rfn
SUPERAntiSpywareRansom.Filecoder/Variant
GDataWin32.Trojan-Ransom.BTCWare.E
AhnLab-V3Trojan/Win32.Scatter.C1976243
McAfeeGenericRXAA-FA!C6E224C8442C
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agentb
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_BTCWARE.F117F2
YandexTrojan.GenAsa!avPO/XVNMxQ
IkarusTrojan-Ransom.BTCWare
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.E8166!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwsBsO8A

How to remove Generic.Ransom.BTCWare.E220ACC5?

Generic.Ransom.BTCWare.E220ACC5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment