Categories: Ransom

Generic.MSIL.Ransomware.Jigsaw.CA34136B (file analysis)

The Generic.MSIL.Ransomware.Jigsaw.CA34136B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Ransomware.Jigsaw.CA34136B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.MSIL.Ransomware.Jigsaw.CA34136B?


File Info:

crc32: E083900Cmd5: 1d82a4d87c8664749a2b8d82775fa8d2name: 1D82A4D87C8664749A2B8D82775FA8D2.mlwsha1: 6bf704d0dcbedf37eaeb04239617d3752fbde19fsha256: c580aa180f875b424f0decf0ee92b8c8c72cf060034378efe29eca395e69bd47sha512: 57c99bf9b6373297e1e3780a5dc7bea430c8e8a451b32cef75f7414ac3e671fe935c50088bdf327537598d637e5beb7a12828497dbbe8fdf4bc4c6130c099ff2ssdeep: 24576:Flw5UL2LWFxbzz1/4b4UEbDqMMq1l3BLotRX68Rc535mgYGvf37kmAbrxfYsYa7:FeeL2LQ9zz24vvqMMqzBstXK5pmg7vAtype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa92017, Inc. All Rights Reserved.InternalName: loaderFileVersion: 3.5.0.44990CompanyName: LoaderSpecialBuild: stable35 stableProductName: LoaderProductVersion: 3.5.0.44790FileDescription: WinOriginalFilename: loaderTranslation: 0x0409 0x04e4

Generic.MSIL.Ransomware.Jigsaw.CA34136B also known as:

K7AntiVirus Trojan ( 0053fc801 )
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
ALYac Generic.MSIL.Ransomware.Jigsaw.CA34136B
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW Trojan ( 0053fc801 )
Cybereason malicious.87c866
Symantec ML.Attribute.HighConfidence
ESET-NOD32 multiple detections
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Kaspersky HEUR:Trojan-Banker.MSIL.BitStealer.gen
BitDefender Generic.MSIL.Ransomware.Jigsaw.CA34136B
NANO-Antivirus Trojan.Win32.Jigsaw.fbkpmu
MicroWorld-eScan Generic.MSIL.Ransomware.Jigsaw.CA34136B
Tencent Win32.Trojan.Generic.Eaxm
Ad-Aware Generic.MSIL.Ransomware.Jigsaw.CA34136B
Sophos Troj/Jigsaw-L
F-Secure Trojan.TR/Jigsaw.edpwd
BitDefenderTheta Gen:NN.ZemsilF.34058.xn0@aSua9ami
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Generic.tc
FireEye Generic.mg.1d82a4d87c866474
Emsisoft Generic.MSIL.Ransomware.Jigsaw.CA34136B (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Generic.fefel
Avira TR/Jigsaw.edpwd
eGambit Unsafe.AI_Score_95%
Microsoft Trojan:MSIL/Confuser.UI
Arcabit Generic.MSIL.Ransomware.Jigsaw.CAD8558B
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Generic.MSIL.Ransomware.Jigsaw.CA34136B
McAfee Artemis!1D82A4D87C86
MAX malware (ai score=97)
Malwarebytes Malware.AI.4209406916
Panda Trj/GdSda.A
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/CoinStealer.AA!tr.pws
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
Qihoo-360 Win32/Ransom.Generic.HgIASVYA

How to remove Generic.MSIL.Ransomware.Jigsaw.CA34136B?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Backdoor:Win32/Subseven.2_1 information

The Backdoor:Win32/Subseven.2_1 is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Marsilia.4611 removal tips

The Marsilia.4611 is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

Should I remove “Client-IRC.Win32.mIRC.616”?

The Client-IRC.Win32.mIRC.616 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

About “Barys.67671” infection

The Barys.67671 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/Olmarik.AOF malicious file

The Win32/Olmarik.AOF is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Sdbot.E6D5958D removal guide

The Generic.Sdbot.E6D5958D is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago