Ransom

What is “Generic.MSIL.Ransomware.Jigsaw.959EE8B4”?

Malware Removal

The Generic.MSIL.Ransomware.Jigsaw.959EE8B4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.959EE8B4 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.959EE8B4?


File Info:

crc32: F10FEAB0
md5: 70b642d311621a1373dbb6b92c58d067
name: 70B642D311621A1373DBB6B92C58D067.mlw
sha1: 40d86ca0ff4f4ac46a724cc7c0cbbcb6f7ff05bb
sha256: 537247339396e9a67b45e6e7a445d8f8d00e595084a03a439b32b2a98a983858
sha512: 78a1b76c09cdf5e8083e8a34bc40c6bf5eeab56070798eac45ebe38a545158fb3e42961612b03a7004bfee35d6268d3053fcea18f484ac8f877cdea4bb549df6
ssdeep: 12288:oUE5QY6Y+upy+00vaqhvVvC0dirzFKiNfQh61:E5p6Ytn00vhhNvC0QrzZf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright 2006-2009 Piriform Ltd
InternalName: Recuva
FileVersion: 1, 32, 0, 444
CompanyName: Piriform Ltd
ProductName: Recuva
ProductVersion: 1, 32, 0, 444
FileDescription: Recuva
OriginalFilename: Recuva.exe
Translation: 0x0409 0x04b0

Generic.MSIL.Ransomware.Jigsaw.959EE8B4 also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
McAfeeArtemis!70B642D31162
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.311621
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Phny.qj
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.959EE8B4
NANO-AntivirusTrojan.Win32.Phny.fahsog
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.959EE8B4
TencentWin32.Trojan.Phny.Aguw
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.959EE8B4
SophosML/PE-A + Troj/Jigsaw-L
ComodoMalware@#26mvhz56uv8na
BitDefenderThetaGen:NN.ZemsilF.34670.Cm0@aabwQHoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.70b642d311621a13
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.959EE8B4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fefel
AviraTR/Jigsaw.tfrtz
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:MSIL/Confuser.UI
ArcabitGeneric.MSIL.Ransomware.Jigsaw.959EE8B4
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.MSIL.Ransomware.Jigsaw.959EE8B4
AhnLab-V3Trojan/Win32.RL_Agent.C4037984
MAXmalware (ai score=97)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
RisingTrojan.Generic!8.C3 (CLOUD)
IkarusTrojan.MSIL.NanoCore
FortinetMSIL/CoinStealer.AA!tr.pws
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.Ransomware.Jigsaw.959EE8B4?

Generic.MSIL.Ransomware.Jigsaw.959EE8B4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment