Ransom

Generic.Ransom.JaffCrypt.B9196646 removal guide

Malware Removal

The Generic.Ransom.JaffCrypt.B9196646 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.JaffCrypt.B9196646 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generic.Ransom.JaffCrypt.B9196646?


File Info:

name: AC31B0076AB918A12901.mlw
path: /opt/CAPEv2/storage/binaries/b0dfb238c29eebea45d0381f3596c78d6fcefd33952df958e27cb2878e274fbf
crc32: E3427B5F
md5: ac31b0076ab918a12901cfd36edda09b
sha1: 2d7442becddf9d451f37ba5ffa98e8199526ccb9
sha256: b0dfb238c29eebea45d0381f3596c78d6fcefd33952df958e27cb2878e274fbf
sha512: e1e8e673af5b9f6c1edf1a0d99bdd6f4f18ff3d07875d017967ced40fffaa78050075e4bbe8655ee5ac061bbd6c6a9a8615d3a63f5358aaf27e229a0fd28c477
ssdeep: 192:bwEoil/3liUJzCA0SuS4wynN5swWZG9prXTT+NUh5tMeA8vu4YCFvP1foJ09gBlp:UEoifLzCA0PyyDjZrDVo7uZ609Iv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151723B6ADD350B22D1F688B02ABE3955E57C5067A76870EBFEC40D8A5E7D0C33070E92
sha3_384: 4b4da35b52dc3e4e4334d2c6b73ff2b0e4561af1b122318c5101a8206e28d4069da0b996e28214cc78e21faa29c0d385
ep_bytes: 558bec83e4f883ec106a00ff15144140
timestamp: 2017-05-16 14:30:21

Version Info:

0: [No Data]

Generic.Ransom.JaffCrypt.B9196646 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.JaffCrypt.B9196646
FireEyeGeneric.mg.ac31b0076ab918a1
ALYacGeneric.Ransom.JaffCrypt.B9196646
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5314
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050e45b1 )
AlibabaTrojan:Win32/EncPk.160a52a8
K7GWTrojan ( 0050e45b1 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Jaff.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGeneric.Ransom.JaffCrypt.B9196646
NANO-AntivirusTrojan.Win32.FileCoder.epwehf
AvastWin32:Malware-gen
TencentWin32.Trojan.Filecoder.Yolw
Ad-AwareGeneric.Ransom.JaffCrypt.B9196646
SophosML/PE-A + Mal/EncPk-OJ
ComodoMalware@#1mr07g6zo0i13
DrWebTrojan.Siggen7.23263
VIPREGeneric.Ransom.JaffCrypt.B9196646
McAfee-GW-EditionBehavesLike.Win32.Rootkit.lh
Trapminemalicious.high.ml.score
EmsisoftGeneric.Ransom.JaffCrypt.B9196646 (B)
SentinelOneStatic AI – Suspicious PE
GDataGeneric.Ransom.JaffCrypt.B9196646
AviraHEUR/AGEN.1234158
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitGeneric.Ransom.JaffCrypt.BD8C5466
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GoogleDetected
AhnLab-V3Malware/Win32.Ransom_.C2295428
McAfeeArtemis!AC31B0076AB9
VBA32BScope.TrojanRansom.Jaff
RisingRansom.Jaffrans!8.E7AB (TFE:2:E3Fbu5wezkV)
YandexTrojan.Filecoder!TrIEC0mxzHg
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder_Jaff.A!tr
BitDefenderThetaAI:Packer.EA94067B1F
AVGWin32:Malware-gen
Cybereasonmalicious.76ab91
PandaTrj/GdSda.A

How to remove Generic.Ransom.JaffCrypt.B9196646?

Generic.Ransom.JaffCrypt.B9196646 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment