Ransom

Generic.MSIL.Ransomware.Jigsaw.13490FCD removal guide

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.13490FCD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.13490FCD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.13490FCD?


File Info:

crc32: D280C14E
md5: 661317e99d9db39ea99ec74567148df0
name: 661317E99D9DB39EA99EC74567148DF0.mlw
sha1: 8c2dedb90580d39c0f206f5c942564482e671a77
sha256: 174d274ba856c587f8f976a034cd1e79002befc8d9bb192dbf5a4a8b46f376c0
sha512: 6f63828965c606f22c97fe18c1c609f29acfbaeb06daba67726cf2245cdfa0220d205fdcb5d714ab519de15fc34a5063a9fe26a8dd289f2ced0d41dad87759a2
ssdeep: 1536:973zfnnKHmgpNsNIZUY1sIzYi7D10Py71T:97jSHXpNsCZUYxYID6I
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: JigsawRansomware.exe
FileVersion: 1
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1
FileDescription:
OriginalFilename: JigsawRansomware.exe

Generic.MSIL.Ransomware.Jigsaw.13490FCD also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.EncoderNET.1
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S6056063
ALYacGeneric.MSIL.Ransomware.Jigsaw.13490FCD
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.99d9db
CyrenW32/Filecoder.AQ.gen!Eldorado
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/Filecoder.Jigsaw.B
APEXMalicious
AvastMSIL:JigSaw-A [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.13490FCD
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.13490FCD
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.13490FCD
SophosML/PE-A + Troj/Jigsaw-K
F-SecureHeuristic.HEUR/AGEN.1140783
BitDefenderThetaGen:NN.ZemsilF.34050.dm0@amCXwWb
TrendMicroRansom.MSIL.JIGSAW.SM
McAfee-GW-EditionRansom-Jigsaw!661317E99D9D
FireEyeGeneric.mg.661317e99d9db39e
EmsisoftTrojan-Ransom.Jigsaw (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1140783
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.18E
MicrosoftRansom:MSIL/JigsawLocker.A
ArcabitGeneric.MSIL.Ransomware.Jigsaw.D34B2FCD
GDataGeneric.MSIL.Ransomware.Jigsaw.13490FCD
AhnLab-V3Win-Trojan/JigsawLocker.Gen
McAfeeRansom-Jigsaw!661317E99D9D
MAXmalware (ai score=81)
MalwarebytesRansom.Jigsaw
TrendMicro-HouseCallRansom.MSIL.JIGSAW.SM
IkarusTrojan-Ransom.JigSaw
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Jigsaw.D!tr.ransom
AVGMSIL:JigSaw-A [Trj]
Qihoo-360HEUR/QVM03.0.017B.Malware.Gen

How to remove Generic.MSIL.Ransomware.Jigsaw.13490FCD?

Generic.MSIL.Ransomware.Jigsaw.13490FCD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment