Ransom

Generic.MSIL.Ransomware.Jigsaw.800C8DB4 malicious file

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.800C8DB4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.800C8DB4 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.800C8DB4?


File Info:

crc32: EF53430F
md5: bab0b715fb65e2576431010550ca1226
name: BAB0B715FB65E2576431010550CA1226.mlw
sha1: 117a5f13d1a710aac2287d1f83a66efcce1215c0
sha256: 428773457045fda14753b07ebc4dd0b1342e9e31096ca7855133c893645d8ced
sha512: e1b51ab6da898a3ed8b954f9b7a5187cf19fd0954a66f5bf46ba2fa83b91b6fb5b6aa7b38817097cc419f3c2089fb2033fef07b6f5e67f9509926d238bd1f670
ssdeep: 24576:Gtqr0V01EUSjITdlKB89AARMw9Ab+6UrW3lj6XMlZxNcM61p0uTDplyI5cHtCU:dwWbTz9NsRDjYgvcM61pvnLct
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2011-2012 by Mikalai Kalpinski. All right reserved.
Assembly Version: 1.3.29.0
InternalName: OrangeHeap.exe
FileVersion: 1.3.29.0
CompanyName: Mikalai Kalpinski
ProductName: Orange Heap
ProductVersion: 1.3.29.0
FileDescription: OrangeHeap
OriginalFilename: OrangeHeap.exe
Translation: 0x0000 0x04b0

Generic.MSIL.Ransomware.Jigsaw.800C8DB4 also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.800C8DB4
CylanceUnsafe
ZillyaTrojan.CoinStealer.Win32.478
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.5fb65e
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.800C8DB4
NANO-AntivirusTrojan.Win32.CoinStealer.euvxiz
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.800C8DB4
TencentWin32.Trojan.Generic.Pijo
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.800C8DB4
SophosMal/Generic-S + Mal/Stealer-E
BitDefenderThetaGen:NN.ZemsilF.34758.Wn0@airs7Cg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.bab0b715fb65e257
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.800C8DB4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Reconyc.l
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2281A5A
MicrosoftRansom:MSIL/JigsawLocker.A
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.MSIL.Ransomware.Jigsaw.800C8DB4
McAfeeArtemis!BAB0B715FB65
MAXmalware (ai score=99)
MalwarebytesRansom.Jigsaw
PandaTrj/GdSda.A
YandexTrojan.Agent!Qm7HKfqWKKo
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.800C8DB4?

Generic.MSIL.Ransomware.Jigsaw.800C8DB4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment