Ransom

Should I remove “Generic.Ransom.Magniber.0AE5F800”?

Malware Removal

The Generic.Ransom.Magniber.0AE5F800 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Magniber.0AE5F800 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Generic.Ransom.Magniber.0AE5F800?


File Info:

crc32: C157F6B7
md5: b0380357f8b5a50e46e7c35aa1427bf6
name: B0380357F8B5A50E46E7C35AA1427BF6.mlw
sha1: 35647d66e2c07874f87575a75b035fce619298c0
sha256: 9eba35656c6590f68a106bbe69b2d5bcb0f682a3271ffc82e3f410c73c730fa4
sha512: 07245beba99bb4a4737b4c7b76beced3a8336cb4ef3ca7c2d66f2f637d8ed771d31ab425e873d73d29d62b790e7a71bfa3e11b267f032b2f38659383244b0742
ssdeep: 3072:1xO6TdIayS6KqSyeQTMkTX1PB2ikY7Vj26K:PCpS6PSyxMqlPBJpH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Uspoken
InternalName: seemly
FileVersion: 7.8
CompanyName: Uspoken
ProductName: seemly retypes csw
ProductVersion: 7.8
FileDescription: seemly nothus
OriginalFilename: seemly.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Magniber.0AE5F800 also known as:

K7AntiVirusTrojan ( 0051c8bc1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Magniber.0AE5F800
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2639763
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Cerber.f3addbae
K7GWTrojan ( 0051c8bc1 )
Cybereasonmalicious.7f8b5a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYLT
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Magniber.0AE5F800
NANO-AntivirusTrojan.Win32.Kryptik.evutbv
MicroWorld-eScanDeepScan:Generic.Ransom.Magniber.0AE5F800
TencentWin32.Trojan.Generic.Pboq
Ad-AwareDeepScan:Generic.Ransom.Magniber.0AE5F800
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#37kycm3rz4ioz
BitDefenderThetaAI:Packer.4E512EBD1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.b0380357f8b5a50e
EmsisoftDeepScan:Generic.Ransom.Magniber.0AE5F800 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1113895
Antiy-AVLTrojan/Generic.ASMalwS.22DE0EA
MicrosoftRansom:Win32/Avaddon.P!MSR
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.Magniber.0AE5F800
Acronissuspicious
McAfeeRansomware-GIX!B0380357F8B5
MAXmalware (ai score=98)
VBA32BScope.Trojan.Encoder
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:OOaSHhIfh7aZf05nbup4gQ)
YandexTrojan.Agent!3QizXR0SxNs
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Magniber.0AE5F800?

Generic.Ransom.Magniber.0AE5F800 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment