Ransom

Generic.MSIL.Ransomware.Jigsaw.35B16B4E (file analysis)

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.35B16B4E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.35B16B4E virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.MSIL.Ransomware.Jigsaw.35B16B4E?


File Info:

crc32: 6C30378F
md5: 3b5389f792095ea2719e3b2790a3eeed
name: 3B5389F792095EA2719E3B2790A3EEED.mlw
sha1: caf175ce6e4896b8407cce82a584ab023fbb0b42
sha256: cde9eab129a0e99fe20c7d8203701b44ff25e3e187b94cec92649a3b1aee95b5
sha512: dd849df2b595b6030ac11d4485cbb80946e7eca0fd782d3c399ed56a35ecb88f1541db62d5fbc5a4ebc4791d0a26af89a106d67899810316cf8531a1fb5ce094
ssdeep: 6144:KZlpp67ge/LahNGUZtRzJfOgHzToFzmkzDdjAj5TNZSQcwYoFu+:epAke/LaGULX3PqKqERKQcwYov
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 2020 Tor Browser developers. All rights reserved.
Assembly Version: 25.1.4.1989
InternalName: at2020.exe
FileVersion: 25.1.4.1989
ProductName: Host Process for Windows Tasks
ProductVersion: 25.1.4.1989
FileDescription: Host Process for Windows Tasks
OriginalFilename: at2020.exe

Generic.MSIL.Ransomware.Jigsaw.35B16B4E also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.32736
CynetMalicious (score: 99)
CAT-QuickHealTrojan.AgentFC.S17036082
ALYacGeneric.MSIL.Ransomware.Jigsaw.35B16B4E
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/ClipBanker.6c006999
K7GWTrojan ( 700000121 )
Cybereasonmalicious.792095
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/ClipBanker.FL
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.35B16B4E
NANO-AntivirusTrojan.Win32.Fsysna.euofid
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.35B16B4E
TencentWin32.Trojan.Agent.Lkxn
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.35B16B4E
SophosML/PE-A + Troj/Jigsaw-K
BitDefenderThetaGen:NN.ZemsilF.34050.wm0@aGyDEjm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3b5389f792095ea2
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.35B16B4E (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128535
MicrosoftRansom:Win32/Jigsaw
ArcabitGeneric.MSIL.Ransomware.Jigsaw.35B16B4E
GDataMSIL.Trojan.ClipBanker.C
AhnLab-V3Trojan/Win32.RL_Generic.C4326041
McAfeeArtemis!3B5389F79209
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
IkarusTrojan.MSIL.PSW
FortinetMSIL/Jigsaw.K!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOgA

How to remove Generic.MSIL.Ransomware.Jigsaw.35B16B4E?

Generic.MSIL.Ransomware.Jigsaw.35B16B4E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment