Ransom

Should I remove “Ransom.Amnesia”?

Malware Removal

The Ransom.Amnesia is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Amnesia virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Amnesia?


File Info:

crc32: 25659C31
md5: edf0effb206652c1bf709b3427c1ac8c
name: EDF0EFFB206652C1BF709B3427C1AC8C.mlw
sha1: aa810e98d7434892eb6ea4036c78faf862f7b5a7
sha256: 79dec62f6b66eef1ff6e022a0a4decdde4bd72c26ee67e572878da65b9a90550
sha512: 294343e5b081f8d9e05642f2c9f77aa10b21183c86a12a05089e8e4570c10d0306a15ccbdd3755d5bedc058aba25533ed4c7bd2f68f119fc4a5c4fdab077e144
ssdeep: 6144:UK9qhLHhWu/nHx8+Z0U1B8UOWBWzv/tcc5x3ZiCvlg:UbHhWu/HGi938UUjx3ZiKl
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom.Amnesia also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26375
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.5AB71F36
FireEyeGeneric.mg.edf0effb206652c1
McAfeeGenericRXDM-JB!EDF0EFFB2066
MalwarebytesRansom.Amnesia
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f700b1 )
BitDefenderDeepScan:Generic.Ransom.Amnesia.5AB71F36
K7GWTrojan ( 004f700b1 )
Cybereasonmalicious.b20665
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/Higuniel.a3f7864b
NANO-AntivirusTrojan.Win32.Filecoder.fgxqox
RisingRansom.Generic!8.E315 (CLOUD)
Ad-AwareDeepScan:Generic.Ransom.Amnesia.5AB71F36
EmsisoftDeepScan:Generic.Ransom.Amnesia.5AB71F36 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureTrojan.TR/Downloader.Gen
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A
IkarusTrojan-Ransom.FileCrypter
eGambitUnsafe.AI_Score_99%
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
MicrosoftRansom:Win32/Amnesia.DSA!MTB
ArcabitDeepScan:Generic.Ransom.Amnesia.5AB71F36
AhnLab-V3Trojan/Win32.Dynamer.C2640962
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.5AB71F36
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Filecoder.FS
Acronissuspicious
VBA32BScope.Trojan.Encoder
ALYacTrojan.Ransom.Scarab
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
TencentWin32.Trojan.Filecoder.Apwi
YandexTrojan.GenAsa!WHz4WMojnlY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Msht.GJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Amnesia.HwUB6zsA

How to remove Ransom.Amnesia?

Ransom.Amnesia removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment