Ransom

MSIL:Ransom-AX [Trj] (file analysis)

Malware Removal

The MSIL:Ransom-AX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Ransom-AX [Trj] virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine MSIL:Ransom-AX [Trj]?


File Info:

crc32: 59E429D4
md5: 3d345419aefc5cbbfab08f657fc5a46a
name: 3D345419AEFC5CBBFAB08F657FC5A46A.mlw
sha1: 78973cfaa8ec59799b12ae03a7c78d54a29c85ed
sha256: 4aac54d8eae00307b1e53ac984b12d7f5aa5a9817d00e7b98c678b8892211ba1
sha512: bb5568b732fa47ff7a0a6ddddceb7424c3fc5e48daea79d20be5aa338f88ea8a896fecaf494ec1b58619d4d1d0ab4f3b572bb4690a8aecda77f031d6d6d7f32a
ssdeep: 6144:0UgDn7iOV7n1MDGXhAd705ZSlkTfMLJTOAZiYSXjjeqXus:L2n7iOVb1PX+705ZUkTfMLJTOAZiYSX
type: PE32+ executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 1999-2012 Firefox and Mozzilla developers. All rights reserved.
Assembly Version: 37.0.2.5583
InternalName: BitcoinBlackmailer.exe
FileVersion: 37.0.2.5583
CompanyName:
LegalTrademarks:
Comments:
ProductName: Firefox
ProductVersion: 37.0.2.5583
FileDescription: Firefox
OriginalFilename: BitcoinBlackmailer.exe

MSIL:Ransom-AX [Trj] also known as:

Elasticmalicious (high confidence)
CAT-QuickHealRansom.Jigsaw.B5
ALYacTrojan.Ransom.Jigsaw.A
MalwarebytesRansom.FileCryptor
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
Cybereasonmalicious.9aefc5
CyrenW64/Jigsaw.B
SymantecRansom.Jigsaw
ESET-NOD32a variant of MSIL/Filecoder.Jigsaw.B
APEXMalicious
AvastMSIL:Ransom-AX [Trj]
ClamAVWin.Ransomware.Jigsaw-6866216-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Jigsaw.A
SUPERAntiSpywareTrojan.Agent/Gen-Multi
MicroWorld-eScanTrojan.Ransom.Jigsaw.A
Ad-AwareTrojan.Ransom.Jigsaw.A
SophosML/PE-A + Troj/Jigsaw-M
F-SecureHeuristic.HEUR/AGEN.1116474
BitDefenderThetaGen:NN.ZexaF.34686.ruW@am@JiRm
VIPRETrojan.MSIL.Filecoder.b (v)
TrendMicroRansom.MSIL.JIGSAW.SMI
McAfee-GW-EditionBehavesLike.Win64.Picsys.dc
FireEyeTrojan.Ransom.Jigsaw.A
EmsisoftTrojan.Ransom.Jigsaw.A (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116474
MicrosoftRansom:MSIL/JigsawLocker.A
ArcabitTrojan.Ransom.Jigsaw.A
GDataMSIL.Trojan-Ransom.Jigsaw.F
AhnLab-V3Win-Trojan/JigsawLocker.Gen
McAfeeRansom-Jigsaw!3D345419AEFC
MAXmalware (ai score=81)
TrendMicro-HouseCallRansom.MSIL.JIGSAW.SMI
RisingRansom.Jigsaw!1.C168 (CLASSIC)
IkarusTrojan-Ransom.JigSaw
FortinetMSIL/Filecoder.8296!tr.ransom
AVGMSIL:Ransom-AX [Trj]

How to remove MSIL:Ransom-AX [Trj]?

MSIL:Ransom-AX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment