Ransom

Generic.MSIL.Ransomware.Jigsaw.27852FD1 information

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.27852FD1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.27852FD1 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.MSIL.Ransomware.Jigsaw.27852FD1?


File Info:

crc32: 55AA3B4E
md5: 71acd0db4e99ffa0c0f297669fba9055
name: 71ACD0DB4E99FFA0C0F297669FBA9055.mlw
sha1: 6050fce7a3b7632af66636c76e118fdb360a6b64
sha256: 124dd27c11bce162dc1f78cfe62da1cdb84e507fe6adbf7d0626447285b3d9f6
sha512: 71ef7b847cc60ef4a891f7df2267498e07798ae3a7ed5eddae33c03b119c13ca6a5ef4e3d6af3630569ecb8db57ec45cb7beb2abd4e14d85d33de7de56a90b17
ssdeep: 6144:bx4IL5QKmJxuXmUE9yOjbaIC+MDPukAuNaWorfdDJPNpSziO:6IL5Qx2mUEJbatbPuC4WoBDZNo1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Runtime Engine Copyright xa9 2015 MadByte Games (www.madbytegames.com)
InternalName: ams_launch
FileVersion: 1.16.11.28
CompanyName: MadByte Games
Comments: Created with AutoPlay Media Studio (www.indigorose.com)
ProductName: Zula Game
ProductVersion: 1.18.2.23
FileDescription: Zula Launcher
OriginalFilename: zula_launcher.exe
Translation: 0x0409 0x0000

Generic.MSIL.Ransomware.Jigsaw.27852FD1 also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.2846
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.27852FD1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.b4e99f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.27852FD1
NANO-AntivirusTrojan.Win32.CoinStealer.ezbrif
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.27852FD1
TencentWin32.Trojan.Generic.Agvc
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.27852FD1
SophosMal/Generic-R + Mal/Stealer-E
BitDefenderThetaGen:NN.ZemsilF.34690.rm0@aSFR2Tbi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.71acd0db4e99ffa0
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.27852FD1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2512C52
MicrosoftRansom:MSIL/JigsawLocker.A
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.MSIL.Ransomware.Jigsaw.27852FD1
AhnLab-V3Trojan/Win32.Ransom.C2446221
McAfeeArtemis!71ACD0DB4E99
MAXmalware (ai score=99)
VBA32Trojan.MulDrop
MalwarebytesRansom.Jigsaw
PandaTrj/GdSda.A
RisingStealer.CoinStealer!8.77F (CLOUD)
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.27852FD1?

Generic.MSIL.Ransomware.Jigsaw.27852FD1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment