Ransom

Should I remove “Ransom:MSIL/JigsawLocker!rfn”?

Malware Removal

The Ransom:MSIL/JigsawLocker!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/JigsawLocker!rfn virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Unusual version info supplied for binary

How to determine Ransom:MSIL/JigsawLocker!rfn?


File Info:

crc32: 1A363547
md5: 6d1cc476e944bee6fa720b5881c9d8ac
name: 6D1CC476E944BEE6FA720B5881C9D8AC.mlw
sha1: c0755e33e5a0557b0e69c7b7b468e93a29e213aa
sha256: e2310969be5df2d897567a540436ccc6cddcd0d2bf0ca87bf3b9550923f9c9ab
sha512: 2130cbfa3e5d4fca72547388e0b3cfdf2c620c5fda11e8ca424891a9f5cf853bb30272b52258bd74c7e3b3dc6522cbb11a4e42d6d417323d4b65f24eb00e73e5
ssdeep: 6144:uHD8+eh3DSS3guO2YBW0avwhQ2+MaqzYOxQ4rCt0O:uHIjpSWvOPBsvwO2+MaqkOo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft Cooporation
Assembly Version: 31.0.1.5411
InternalName: BTC MultiGrabber.exe
FileVersion: 31.0.1.5411
CompanyName:
LegalTrademarks:
Comments:
ProductName: Host Process for Windows Services
ProductVersion: 31.0.1.5411
FileDescription: Host Process for Windows Services
OriginalFilename: BTC MultiGrabber.exe

Ransom:MSIL/JigsawLocker!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0
FireEyeGeneric.mg.6d1cc476e944bee6
CAT-QuickHealTrojan.Fsysna
Qihoo-360Win32/Trojan.385
ALYacDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 004d6a1c1 )
BitDefenderDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0
K7GWPassword-Stealer ( 004d6a1c1 )
Cybereasonmalicious.6e944b
BitDefenderThetaGen:NN.ZemsilF.34590.wm0@a0Y22rf
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Fsysna.ekia
AlibabaTrojan:Win32/Fsysna.47c1e820
NANO-AntivirusTrojan.Win32.BitCoinMiner.eqjvns
ViRobotTrojan.Win32.Z.Fsysna.373760
TencentMalware.Win32.Gencirc.114b07a9
Ad-AwareDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0
EmsisoftDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0 (B)
ComodoMalware@#22ezzcu3eofsp
F-SecureHeuristic.HEUR/AGEN.1101058
DrWebTrojan.MulDrop7.28891
ZillyaTrojan.Fsysna.Win32.14648
TrendMicroRansom.MSIL.JIGSAW.SMB
McAfee-GW-EditionGenericRXBW-AA!6D1CC476E944
SophosMal/Generic-R + Troj/Jigsaw-K
IkarusTrojan.MSIL.PSW
JiangminTrojan.Fsysna.hqz
AviraHEUR/AGEN.1101058
Antiy-AVLTrojan/Win32.Fsysna
MicrosoftRansom:MSIL/JigsawLocker!rfn
ArcabitDeepScan:Generic.MSIL.Ransomware.Jigsaw.6416D1F0
ZoneAlarmTrojan.Win32.Fsysna.ekia
GDataMSIL.Trojan.ClipBanker.C
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.RL_Fsysna.C4249603
McAfeeGenericRXBW-AA!6D1CC476E944
MAXmalware (ai score=89)
VBA32Trojan.Fsysna
MalwarebytesTrojan.BitCoinStealer
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/PSW.CoinStealer.Z
TrendMicro-HouseCallRansom.MSIL.JIGSAW.SMB
RisingRansom.JigsawLocker!8.52DD (CLOUD)
YandexTrojan.Fsysna!I6KV0IYl2MA
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Jigsaw.K!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:MSIL/JigsawLocker!rfn?

Ransom:MSIL/JigsawLocker!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment