Ransom

What is “Generic.MSIL.Ransomware.Jigsaw.1CE0FC54”?

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.1CE0FC54 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.1CE0FC54 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.1CE0FC54?


File Info:

crc32: FF262472
md5: 50e4cbca355a76b9401a79037a17723e
name: 50E4CBCA355A76B9401A79037A17723E.mlw
sha1: 789cac4f659c5a6265802d4a87ee70e70bda60e4
sha256: af5faba437e43802b5d410fceb3a4463c0946648406dc6de7ff0b7dd6e1c7d7e
sha512: 9dcc135cef00a5cd9784c55fe5e08c2af9ab065932b2fe2b2562683c65d43811242878ac75ba6fa25cbc3e74f2ff3c41270d2158a21a962bb71abfd79baf5d9f
ssdeep: 12288:cEZ1zHqwe8kXO3WdBrkFpbKpmGUdZGi0jMdhhSKKVdib+zJfAOc91MgG83:pzKH8kXOmsp8qdZZ0j00u6N1R2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright(C) 2013 by FtpScripter
InternalName: FtpScripter Editor
FileVersion: 2.0.5.25
CompanyName: Scripter
LegalTrademarks: FtpScripter
ProductName: FtpScripter
ProductVersion: 2.0
FileDescription: FtpScripter Editor
OriginalFilename: FtpScripterEditor.exe
Translation: 0x0409 0x04e4

Generic.MSIL.Ransomware.Jigsaw.1CE0FC54 also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.52278
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:MSIL/Confuser.1e779ea7
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.a355a7
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.BitStealer.gen
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54
NANO-AntivirusTrojan.Win32.Confuser.euuwkg
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54
TencentWin32.Trojan.Generic.Swbc
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54
SophosTroj/Jigsaw-L
BitDefenderThetaGen:NN.ZemsilF.34758.Pm0@aeBcTpai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.50e4cbca355a76b9
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bodyj
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1109336
Antiy-AVLTrojan/Generic.ASMalwS.228A1D7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Confuser.UI
GDataGeneric.MSIL.Ransomware.Jigsaw.1CE0FC54
AhnLab-V3Trojan/Win32.Ransomlock.R217840
McAfeeArtemis!50E4CBCA355A
MAXmalware (ai score=100)
MalwarebytesMalware.AI.849276241
PandaTrj/GdSda.A
YandexTrojan.Agent!JF3ZAweDYE8
IkarusTrojan.MSIL.NanoCore
FortinetMSIL/CoinStealer.AA!tr.pws
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.1CE0FC54?

Generic.MSIL.Ransomware.Jigsaw.1CE0FC54 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment