Ransom

How to remove “Generic.MSIL.Ransomware.Jigsaw.83140972”?

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.83140972 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.83140972 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.MSIL.Ransomware.Jigsaw.83140972?


File Info:

crc32: EE7000DD
md5: c2034aebd44ceaf274867a99f31b91bd
name: C2034AEBD44CEAF274867A99F31B91BD.mlw
sha1: db784e9d79ca8461fd17e6a24adaf47d0d699aa8
sha256: 2899180409b64572d3c147caae83b57cf06962ad500ac8d1efe12d89a24761c7
sha512: a7a46eb13ae7c0453b74f8a217236f6ebdcd303d3d51ede5873200984a6706c67518a629abe9b473844cd361018c7a17f89eac7d78a039155343029f49c9a341
ssdeep: 3072:pcTGqz55Bp8a8y8Irk9c6hxbIoRJntRLy8Irk9c6hxbIoRJntRvA3:o7j/F8y8Pc6zsoRdtRLy8Pc6zsoRdtR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: fichier.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: fichier.exe

Generic.MSIL.Ransomware.Jigsaw.83140972 also known as:

LionicTrojan.Win32.Jigsaw.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.30196
ALYacTrojan.Ransom.Jigsaw
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.8935
AlibabaTrojan:MSIL/JigsawLocker.48bef24e
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
CyrenW32/MSIL_Agent.BZT.gen!Eldorado
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/Filecoder.Jigsaw.B
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.83140972
NANO-AntivirusTrojan.Win32.Filecoder.fnhlpn
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.83140972
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.83140972
SophosMal/Generic-R + Mal/Jigsaw-A
BitDefenderThetaGen:NN.ZemsilF.34142.km0@amxEASe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_JIGSAW.SM
McAfee-GW-EditionGenericRXDW-TQ!C2034AEBD44C
FireEyeGeneric.mg.c2034aebd44ceaf2
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.83140972 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.lbcj
AviraHEUR/AGEN.1126343
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2AA7701
MicrosoftRansom:MSIL/JigsawLocker.A
ArcabitGeneric.MSIL.Ransomware.Jigsaw.D4F4A16C
GDataGeneric.MSIL.Ransomware.Jigsaw.83140972
AhnLab-V3Trojan/Win32.RL_Jigsaw.C3527835
McAfeeGenericRXDW-TQ!C2034AEBD44C
MAXmalware (ai score=94)
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.Jigsaw.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_JIGSAW.SM
RisingRansom.Jigsaw!1.D974 (CLASSIC)
YandexTrojan.Filecoder!mh6TBIxjMzM
IkarusTrojan-Ransom.JigSaw
MaxSecureTrojan.Malware.73694066.susgen
FortinetMSIL/Filecoder_Jigsaw.A!tr.ransom
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.83140972?

Generic.MSIL.Ransomware.Jigsaw.83140972 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment