Ransom

What is “Generic.Ransom.Stampado.69B659C7”?

Malware Removal

The Generic.Ransom.Stampado.69B659C7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Stampado.69B659C7 virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.Ransom.Stampado.69B659C7?


File Info:

crc32: A6E6D6F8
md5: 0046e5de7e6b192195d910b3581249e2
name: 0046E5DE7E6B192195D910B3581249E2.mlw
sha1: 02de90fb00293950d9611bfc65d6866f0c9d3d58
sha256: d814886c099509851d8e0c782760fe7b14afc59ba0db8e4be787beea494ccde4
sha512: 355c454def3e458511a8b94849994e8e4993b4551042c71d74d68df10e7f0bcda60e0d8c3df4e715cc5c9972f1c9a0710550baa98d5082ac501d8fbf145f05d5
ssdeep: 12288:yBw4tn8y3AGmEvX+3IdpvX5E6opcLyXTHsXzvHh00vF:YFtNfmEvX+i/hopIyDkV
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Generic.Ransom.Stampado.69B659C7 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050b4a81 )
DrWebTrojan.Encoder.7161
CynetMalicious (score: 100)
CAT-QuickHealRansom.Autoit.Stampado.A
ALYacGeneric.Ransom.Stampado.69B659C7
CylanceUnsafe
SangforRansom.Win32.Stampado.69B659C7
K7GWTrojan ( 0050b4a81 )
Cybereasonmalicious.e7e6b1
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Filecoder.Philadelphia.G
APEXMalicious
AvastINF:AutoRun-BI [Wrm]
ClamAVWin.Ransomware.Stampado-9796884-0
KasperskyHEUR:Worm.Script.Generic
BitDefenderGeneric.Ransom.Stampado.69B659C7
NANO-AntivirusTrojan.Script.AuVir.ekpekr
MicroWorld-eScanGeneric.Ransom.Stampado.69B659C7
TencentWin32.Worm.Filecoder.Bnq
Ad-AwareGeneric.Ransom.Stampado.69B659C7
SophosTroj/Stampado-A
BitDefenderThetaAI:Packer.618F1AC817
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.hc
FireEyeGeneric.mg.0046e5de7e6b1921
EmsisoftGeneric.Ransom.Stampado.69B659C7 (B)
JiangminTrojan.Inject.asio
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_52%
MicrosoftRansom:Win32/Stampado.A
ArcabitGeneric.Ransom.Stampado.69B659C7
GDataGeneric.Ransom.Stampado.69B659C7 (3x)
McAfeeArtemis!0046E5DE7E6B
MAXmalware (ai score=97)
RisingRansom.Philadelphia/Autoit!1.BA48 (CLASSIC)
IkarusWorm.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Philadelphia.E!tr
AVGINF:AutoRun-BI [Wrm]
Paloaltogeneric.ml

How to remove Generic.Ransom.Stampado.69B659C7?

Generic.Ransom.Stampado.69B659C7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment