Ransom

Generic.MSIL.Ransomware.Jigsaw.7999195A removal tips

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.7999195A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.7999195A virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.7999195A?


File Info:

crc32: E40EB3E1
md5: 9caf4e35967a010280cc67fbcbab5a5c
name: 9CAF4E35967A010280CC67FBCBAB5A5C.mlw
sha1: 9d6138896a6f772d43cb4d9cdfd00e21cdde45a2
sha256: f502efe9226bc0a3ac4df207aec62cc7a52386391471a6a91ce7e1be244bacb8
sha512: ef59388492348cc08e38b01f044550dc9a09ad4e74ead1a9befae655c11da2ed5dd0d203a3a901011475cf6dc91073a17b9b05b2748cd8b4d268eeaad8c99912
ssdeep: 6144:c2GMc8ub4cj9ezRQj4T5DOf+RGDmGSapGfJfzbYvOOUk:c2GMc8k4cjC5ydSapOrsvvT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Runtime Engine Copyright xa9 2015 MadByte Games (www.madbytegames.com)
InternalName: ams_launch
FileVersion: 1.16.11.28
CompanyName: MadByte Games
Comments: Created with AutoPlay Media Studio (www.indigorose.com)
ProductName: Zula Game
ProductVersion: 1.18.2.23
FileDescription: Zula Launcher
OriginalFilename: zula_launcher.exe
Translation: 0x0409 0x0000

Generic.MSIL.Ransomware.Jigsaw.7999195A also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.7999195A
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.5967a0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Agent.qwgdth
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.7999195A
NANO-AntivirusTrojan.Win32.CoinStealer.ezckwc
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.7999195A
TencentWin32.Trojan.Agent.Hwwt
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.7999195A
SophosMal/Generic-R + Mal/Stealer-E
ComodoMalware@#jixkk5xgrdrj
BitDefenderThetaGen:NN.ZemsilF.34690.rm0@amVhXCgi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.9caf4e35967a0102
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.7999195A (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2515E71
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:MSIL/JigsawLocker!rfn
GDataGeneric.MSIL.Ransomware.Jigsaw.7999195A
AhnLab-V3Trojan/Win32.CoinStealer.C2469484
McAfeeArtemis!9CAF4E35967A
MAXmalware (ai score=97)
MalwarebytesRansom.Jigsaw
PandaTrj/GdSda.A
RisingStealer.CoinStealer!8.77F (CLOUD)
YandexTrojan.Agent!/I9K5cZe8W8
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinStealer.AA!tr.pws
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.7999195A?

Generic.MSIL.Ransomware.Jigsaw.7999195A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment