Ransom

Generic.MSIL.Ransomware.Jigsaw.2BC74E3B removal guide

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.2BC74E3B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.2BC74E3B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.2BC74E3B?


File Info:

crc32: 9143C878
md5: aaf23e82267700672e1099eaa40a3e8c
name: AAF23E82267700672E1099EAA40A3E8C.mlw
sha1: a03f942e6bf7740b62676191d31c98a639c30a84
sha256: 544b25d455993b480dcb0645b4a2c921a0d58e05ea697d3ecd70cb34be1e9bda
sha512: 2e957dabe01614e8235b9f76bda61c747c1679810e70df75b91da2051bc1abe1e95c30f55e18c87f8d9895264b52f0912be276908829880a54cea3bb5946ce4a
ssdeep: 12288:KM7MVQQjI97wCnfPdXmqxvd8eOMTFuBgmGSsqS87h1RgcD:KVQQGs4f1Xm4vPuxFsqS81fgc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: (c) Angus Johnson 1999-2015
InternalName: ResHack
FileVersion: 4.2.5.146
CompanyName: Angus Johnson
ProductName: ResHack
FileVersion2: Release Candidate 3
ProductVersion: 4.0.0.0
FileDescription: Resource viewer, decompiler & recompiler
OriginalFilename: ResHack
Translation: 0x0409 0x04e4

Generic.MSIL.Ransomware.Jigsaw.2BC74E3B also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.226770
CyrenW32/MSIL_Troj.YS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B
NANO-AntivirusTrojan.Win32.Jigsaw.fahxpf
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B
TencentWin32.Trojan.Generic.Lqyk
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34684.Dm0@a4!Edmni
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.aaf23e8226770067
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cavml
AviraHEUR/AGEN.1109336
MicrosoftRansom:MSIL/JigsawLocker.A
GDataGeneric.MSIL.Ransomware.Jigsaw.2BC74E3B
McAfeeArtemis!AAF23E822677
MAXmalware (ai score=97)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Agent!3TUnw41+ji4
IkarusTrojan.MSIL.Confuser
FortinetMSIL/Agent.REDC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.2BC74E3B?

Generic.MSIL.Ransomware.Jigsaw.2BC74E3B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment