Malware

Heur.Jatif.Gen.1 removal tips

Malware Removal

The Heur.Jatif.Gen.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Jatif.Gen.1 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process

Related domains:

z.whorecord.xyz
a.tomx.xyz
xecuter2.zapto.org

How to determine Heur.Jatif.Gen.1?


File Info:

crc32: D47A2175
md5: 141dc8c1b9464eb2da7fc8fd2f594d42
name: 141DC8C1B9464EB2DA7FC8FD2F594D42.mlw
sha1: 550eceb53d79ea7dd5df4de2414cce71a2e3ec42
sha256: de492464e02facf4a4c9ec8043c0026c0104a525e5dfa52038145abb248f70d0
sha512: 7f79f67c9b469f38b98cee558740fe049613f903dff5ac6dae018ddbd9a5a22eb65fdcfb914458241b0a528ba2cb0780ac7d282782d36e75b8922368b873b59b
ssdeep: 3072:ctjLKxbA3zrIL701RCawZowcNlnBflHXFo+jIIH8/SkP76zgAIF7exOYfDPy4u3:ctjWxbczG4XMoxnBLFIj/d26iDK4u3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Heur.Jatif.Gen.1 also known as:

K7AntiVirusTrojan ( 004e48901 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Stealer.1176
CynetMalicious (score: 99)
ALYacGen:Heur.Jatif.Gen.1
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
AlibabaTrojan:MSIL/Injector.af6fcd54
K7GWTrojan ( 004e48901 )
Cybereasonmalicious.1b9464
SymantecTrojan.ADH
ESET-NOD32a variant of MSIL/Injector.CWS
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Malware.Uztuby-9868432-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Jatif.Gen.1
NANO-AntivirusTrojan.Win32.Agent.cubmrz
MicroWorld-eScanGen:Heur.Jatif.Gen.1
TencentWin32.Trojan.Agent.Duwj
SophosGeneric ML PUA (PUA)
ComodoMalware@#1y1cu2jjwnavg
BitDefenderThetaGen:NN.ZemsilF.34170.km1@aCLSwkj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGen:Heur.Jatif.Gen.1
EmsisoftGen:Heur.Jatif.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1137116
Antiy-AVLTrojan/Generic.ASMalwS.890198
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.Jatif.Gen.1
McAfeeArtemis!141DC8C1B946
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
IkarusTrojan.Win32.Inject
FortinetW32/Agent.AFMQX!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Heur.Jatif.Gen.1?

Heur.Jatif.Gen.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment