Ransom

Generic.MSIL.Ransomware.Jigsaw.7B706B10 (file analysis)

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.7B706B10 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.7B706B10 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.7B706B10?


File Info:

crc32: F4B40B80
md5: 8b70396671e7617c4c1d1f0bcf3739a6
name: 8B70396671E7617C4C1D1F0BCF3739A6.mlw
sha1: 066399e79db46ee0916d6becc4ea5aff179628c7
sha256: 50d0b74726dd4e018654540e0610cb6d0ed2ef5833b884268075f192e0bc4a67
sha512: bde2d4962472803a2261a3f84b1ba6f0aa45f83b4fc929be8d3f6b98a6a601a00b3f632e2bb2ed107be8792b1ba78964b97d6be5cbcbdc2af80536c63227d67b
ssdeep: 6144:D7NEJAY4r4lzZpj6+uu3qJWppMzLm00AuleChPekvaCf15023ltd:D7GJb4r4lzn6o3qJAazL7uleCNcCf1d
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Runtime Engine Copyright xa9 2015 MadByte Games (www.madbytegames.com)
InternalName: ams_launch
FileVersion: 1.16.4.8
CompanyName: WinLoader
Comments: Created with AutoPlay Media Studio (www.indigorose.com)
ProductName: Loader
ProductVersion: 1.17.5
FileDescription: Win Loader
OriginalFilename: Loader.exe
Translation: 0x0409 0x0000

Generic.MSIL.Ransomware.Jigsaw.7B706B10 also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.40499
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.7B706B10
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Stealer.056307a9
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.671e76
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.7B706B10
NANO-AntivirusTrojan.Win32.CoinStealer.essmgv
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.7B706B10
TencentWin32.Trojan.Generic.Ecke
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.7B706B10
SophosMal/Generic-R + Mal/Stealer-E
ComodoMalware@#1xlcafxwr47vw
BitDefenderThetaGen:NN.ZemsilF.34608.rm0@aeH2erai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.8b70396671e7617c
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.7B706B10 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
MicrosoftRansom:MSIL/JigsawLocker.A
ArcabitGeneric.MSIL.Ransomware.Jigsaw.7B706B10
AegisLabTrojan.Win32.Agent.4!c
GDataGeneric.MSIL.Ransomware.Jigsaw.7B706B10
AhnLab-V3Trojan/Win32.MDA.C694979
McAfeeGenericRXCW-CW!8B70396671E7
MAXmalware (ai score=100)
VBA32Trojan.Agent
MalwarebytesRansom.Jigsaw
PandaTrj/GdSda.A
RisingRansom.JigsawLocker!8.52DD (CLOUD)
YandexTrojan.Agent!oFHMLV9ZhAg
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.AA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwMAhjsA

How to remove Generic.MSIL.Ransomware.Jigsaw.7B706B10?

Generic.MSIL.Ransomware.Jigsaw.7B706B10 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment