Ransom

How to remove “Ransom:Win32/Amnesia.VSB!MTB”?

Malware Removal

The Ransom:Win32/Amnesia.VSB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Amnesia.VSB!MTB virus can do?

  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Amnesia.VSB!MTB?


File Info:

crc32: 12552B3D
md5: 3ab4a57a07ef89eece7946735f9e6c11
name: 3AB4A57A07EF89EECE7946735F9E6C11.mlw
sha1: c55687b33c9b040db1e7ec745e696d0f9f4b3d64
sha256: b548dc4d148303cb8d81e9e8a7fd7502154daae0a6ed21060e433cc2adc11e54
sha512: b80d40b19e38b4fbfb2f7f6255e500dfd72093e349a65e02fb2d62fc6f027a4900924cbc0a0c62fb33b59cfa806af1cfec103b90d45a88063d74c1a98fbb8e47
ssdeep: 1536:+SvLopYdTDwM4ve5HpzSDMiKVajIhz3WN8Sgp8/cjRknxx3+62n6Sk:+XpYRwPmZVSDM1phz3WSSS8cRMl2vk
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Amnesia.VSB!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.15028
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.C328E139
FireEyeGeneric.mg.3ab4a57a07ef89ee
Qihoo-360HEUR/QVM05.1.A270.Malware.Gen
McAfeeRansom-Amnesia!3AB4A57A07EF
CylanceUnsafe
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
SangforTrojan.Win32.Save.a
BitDefenderDeepScan:Generic.Ransom.Amnesia.C328E139
Cybereasonmalicious.a07ef8
BitDefenderThetaAI:Packer.0B62D6E41F
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallMal_Purge
AvastWin32:Dh-A [Heur]
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Purga.epxtsw
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazo8kvfnz2B+ZTbq/TnETZvV)
Ad-AwareDeepScan:Generic.Ransom.Amnesia.C328E139
SophosML/PE-A + Mal/DelpDldr-F
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureDropper.DR/Delphi.Gen7
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Sytro.ch
EmsisoftDeepScan:Generic.Ransom.Amnesia.C328E139 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Purga.p
AviraDR/Delphi.Gen7
MAXmalware (ai score=87)
MicrosoftRansom:Win32/Amnesia.VSB!MTB
ArcabitDeepScan:Generic.Ransom.Amnesia.C328E139
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.C328E139
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4294864
Acronissuspicious
VBA32BScope.TrojanRansom.Purga
ALYacDeepScan:Generic.Ransom.Amnesia.C328E139
MalwarebytesMalware.Heuristic.1006
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Filecoder.FS
YandexTrojan.GenAsa!Dy18OPPLTiI
IkarusTrojan.Win32.Lnkhyd
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.FS!tr
AVGWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/Amnesia.VSB!MTB?

Ransom:Win32/Amnesia.VSB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment