Malware

ML/PE-A + Troj/Jigsaw-M (file analysis)

Malware Removal

The ML/PE-A + Troj/Jigsaw-M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Jigsaw-M virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Jigsaw-M?


File Info:

crc32: 5CB72E6A
md5: 1fce13705a1c2b6ab336a115c18d8296
name: 1FCE13705A1C2B6AB336A115C18D8296.mlw
sha1: 385684ab459dae99fb45b77e17c885e15ad9ec12
sha256: 901919573bab545c4a928600926b461de9afe150ecd6d38f9153f345f72769a3
sha512: ab1f28e8cbb5e5b86357a1170ed66bde89e415732f46895fddbd310e0476e1bfe24312102c8bcfa8c50491277ba4376ec160946cb1e7e13fe55ee89d2ee61fa2
ssdeep: 6144:CUgDn7iOV7n1MDGXhAd705ZSlkTfMLJTOAZiYSXjjeqXus:R2n7iOVb1PX+705ZUkTfMLJTOAZiYSX
type: PE32+ executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 1999-2012 Firefox and Mozzilla developers. All rights reserved.
Assembly Version: 37.0.2.5583
InternalName: BitcoinBlackmailer.exe
FileVersion: 37.0.2.5583
CompanyName:
LegalTrademarks:
Comments:
ProductName: Firefox
ProductVersion: 37.0.2.5583
FileDescription: Firefox
OriginalFilename: BitcoinBlackmailer.exe

ML/PE-A + Troj/Jigsaw-M also known as:

K7AntiVirusTrojan ( 004e289f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealRansom.Jigsaw.B5
ALYacTrojan.Ransom.Jigsaw
MalwarebytesRansom.FileCryptor
ZillyaTrojan.Jigsaw.Win32.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/JigsawLocker.c94986dd
K7GWTrojan ( 004e289f1 )
Cybereasonmalicious.05a1c2
CyrenW64/Jigsaw.B
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/Filecoder.Jigsaw.B
APEXMalicious
AvastMSIL:Ransom-AX [Trj]
ClamAVWin.Ransomware.Jigsaw-6866216-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Jigsaw.A
SUPERAntiSpywareTrojan.Agent/Gen-Multi
MicroWorld-eScanTrojan.Ransom.Jigsaw.A
TencentWin32.Trojan.Generic.Edfa
Ad-AwareTrojan.Ransom.Jigsaw.A
SophosML/PE-A + Troj/Jigsaw-M
BitDefenderThetaGen:NN.ZexaF.34758.ruW@a0jdNDe
VIPRETrojan.MSIL.Filecoder.b (v)
TrendMicroRansom.MSIL.JIGSAW.SMI
McAfee-GW-EditionBehavesLike.Win64.Generic.dc
FireEyeTrojan.Ransom.Jigsaw.A
EmsisoftTrojan.Ransom.Jigsaw.A (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116474
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.18E
MicrosoftRansom:MSIL/JigsawLocker.A
ArcabitTrojan.Ransom.Jigsaw.A
AegisLabTrojan.Win32.Generic.4!c
GDataMSIL.Trojan-Ransom.Jigsaw.F
AhnLab-V3Win-Trojan/JigsawLocker.Gen
McAfeeRansom-Jigsaw!1FCE13705A1C
MAXmalware (ai score=100)
PandaTrj/CI.A
TrendMicro-HouseCallRansom.MSIL.JIGSAW.SMI
RisingRansom.Jigsaw!1.C168 (CLASSIC)
IkarusTrojan-Ransom.JigSaw
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.8296!tr.ransom
AVGMSIL:Ransom-AX [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/Jigsaw-M?

ML/PE-A + Troj/Jigsaw-M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment