Ransom

Should I remove “Generic.MSIL.Ransomware.Jigsaw.8B792BB2”?

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.8B792BB2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.8B792BB2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.8B792BB2?


File Info:

crc32: 8F7616C0
md5: f2d194caccccb32a784c9313dd1fa591
name: F2D194CACCCCB32A784C9313DD1FA591.mlw
sha1: 632680c9b8a17d1106b60f8148c59b0ecf5c74d9
sha256: 4b353aceeb98ee90d9276dd7618cde20ff11c05146d80d640a6f80db4057ea36
sha512: a442aa957697a55c34d06a753f0ea7b2ee174ea3ddcb2ff4c2fb7b500d0c53d7510d8b7c24f842feb8b73ffaadb3d5d1a4a4c3762ac089f2fc0c3a40f6d6cd36
ssdeep: 3072:ry8vjqppWy8Irk9c6hxbIoRJntRuy8Irk9c6hxbIoRJntRP:ryPIy8Pc6zsoRdtRuy8Pc6zsoRdtR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Adobe Acrobat Document
Assembly Version: 1.0.0.0
InternalName: Main.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Adobe Acrobat Document
ProductVersion: 1.0.0.0
FileDescription: Main
OriginalFilename: Main.exe

Generic.MSIL.Ransomware.Jigsaw.8B792BB2 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.EncoderNET.2
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S6056063
ALYacTrojan.Ransom.Jigsaw
CylanceUnsafe
ZillyaTrojan.Agent.Win32.927952
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:MSIL/JigsawLocker.70e8d056
K7GWTrojan ( 700000121 )
Cybereasonmalicious.accccb
CyrenW32/Filecoder.AQ.gen!Eldorado
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/Filecoder.Jigsaw.B
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Agent.gen
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.8B792BB2
NANO-AntivirusTrojan.Win32.Filecoder.fgmcyq
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.8B792BB2
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.8B792BB2
SophosMal/Generic-R + Troj/Jigsaw-K
ComodoMalware@#tno2ftzcr2jz
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_JIGSAW.SM
McAfee-GW-EditionGenericRXDW-TQ!F2D194CACCCC
FireEyeGeneric.mg.f2d194caccccb32a
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.8B792BB2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.jzap
AviraHEUR/AGEN.1126343
Antiy-AVLTrojan/Generic.ASMalwS.2789C66
MicrosoftRansom:MSIL/JigsawLocker.A
GDataGeneric.MSIL.Ransomware.Jigsaw.8B792BB2
AhnLab-V3Trojan/Win32.RL_Jigsaw.C3527835
McAfeeGenericRXDW-TQ!F2D194CACCCC
MAXmalware (ai score=100)
MalwarebytesRansom.Jigsaw.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_JIGSAW.SM
RisingRansom.JigsawLocker!8.52DD (CLOUD)
YandexTrojan.Filecoder!ypobPoLCv3o
IkarusTrojan-Ransom.JigSaw
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Jigsaw.D!tr.ransom
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.8B792BB2?

Generic.MSIL.Ransomware.Jigsaw.8B792BB2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment