Ransom

How to remove “Generic.Ransom.Stampado.01CFD00B (B)”?

Malware Removal

The Generic.Ransom.Stampado.01CFD00B (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Stampado.01CFD00B (B) virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Ransom.Stampado.01CFD00B (B)?


File Info:

name: 54484026306831A3BA02.mlw
path: /opt/CAPEv2/storage/binaries/3169a33031f80707882a979cf41e6f5c981ecdf179e896e56bddebda59931350
crc32: F4836EF6
md5: 54484026306831a3ba0243880e3087a8
sha1: 82672bed460eaf44803338b18d1f7b904541cafe
sha256: 3169a33031f80707882a979cf41e6f5c981ecdf179e896e56bddebda59931350
sha512: aa0dfcc9ff3e9a85bbb3bcba9836443712fcd35afabadc137525be350a520d44c652af4a255ca8fa3075377fb8ccec71eab30dce759b8ba0eb5948f6e360baa3
ssdeep: 12288:qtb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSga7TsizikP6A:qtb20pkaCqT5TBWgNQ7a/simkP6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19015AE1373DE8361C3B25273BA65B701AEBF782506A1F96B2FD4093DF920122525E673
sha3_384: 4b12c50b4d65ad77dc78ab851cffd5d7b43d96ef85c975bf76db2582ac749da5e6843a8ea1d7d520a21db8591fae4637
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2017-09-15 08:03:33

Version Info:

Translation: 0x0809 0x04b0

Generic.Ransom.Stampado.01CFD00B (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stampado.4!c
MicroWorld-eScanGeneric.Ransom.Stampado.01CFD00B
ALYacGeneric.Ransom.Stampado.01CFD00B
MalwarebytesRansom.Stampado.AutoIt
SangforSuspicious.Win32.Artemis.544840263068
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.630683
VirITTrojan.Win32.Autoit_c.BHWH
APEXMalicious
BitDefenderGeneric.Ransom.Stampado.01CFD00B
EmsisoftGeneric.Ransom.Stampado.01CFD00B (B)
VIPREGeneric.Ransom.Stampado.01CFD00B
McAfee-GW-EditionBehavesLike.Win32.BadFile.ch
Trapminesuspicious.low.ml.score
FireEyeGeneric.Ransom.Stampado.01CFD00B
SophosMal/Generic-R
GDataGeneric.Ransom.Stampado.01CFD00B (2x)
WebrootW32.Dropper.Gen
ArcabitGeneric.Ransom.Stampado.01CFD00B [many]
McAfeeArtemis!544840263068
MAXmalware (ai score=83)
Cylanceunsafe
MaxSecureTrojan.Malware.186571728.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Generic.Ransom.Stampado.01CFD00B (B)?

Generic.Ransom.Stampado.01CFD00B (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment