Malware

Jaik.101621 information

Malware Removal

The Jaik.101621 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.101621 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Jaik.101621?


File Info:

name: D445185038EC6D785C7A.mlw
path: /opt/CAPEv2/storage/binaries/55bccc422276f7193cc0febd4f7a737ece808c8e8b292b2450a61a24a439a881
crc32: 55C0ED82
md5: d445185038ec6d785c7a9e218e44fe47
sha1: a9985d0d5fe4466dc22d0664576f87eee8cfcc12
sha256: 55bccc422276f7193cc0febd4f7a737ece808c8e8b292b2450a61a24a439a881
sha512: 5bb7c2768e8983ea7aa6b16c4ca4c934d6f5ce7dbf5499d9fc8fa306be1b3b61198ddda55d60530452a41a420a218d490162656328a389e57db291db2c4a7c8c
ssdeep: 393216:IUnK07fppYSixfGtrpSy8UANV/uuVCTy2dAD32nF9Q:V3lb6cNG5N91VUygADmnE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152E62313B1018093D1955AFA933E2B3ABDB857925E70C8B3ABD49DA33C71173EB02957
sha3_384: 9156e6e4a68dc4b28de0ea8f5f2e630ebfafdf93193fb21f754705f7c0d417ae73f09b58b7d7ff274c3ce82f08a8c879
ep_bytes: 60be0060a0008dbe00b09fff5789e58d
timestamp: 2022-11-01 16:23:16

Version Info:

0: [No Data]

Jaik.101621 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Jaik.101621
FireEyeGeneric.mg.d445185038ec6d78
CylanceUnsafe
SangforTrojan.Win32.Save.BlackMoon
Cybereasonmalicious.d5fe44
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderGen:Variant.Jaik.101621
Ad-AwareGen:Variant.Jaik.101621
EmsisoftGen:Variant.Jaik.101621 (B)
VIPREGen:Variant.Jaik.101621
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.BlackMoon.D
GoogleDetected
AviraHEUR/AGEN.1243809
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASCommon.218
ArcabitTrojan.Jaik.D18CF5
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C5299653
BitDefenderThetaGen:NN.ZexaF.34754.@pJfaKnPJ9eb
ALYacGen:Variant.Jaik.101621
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!76JnOyIxZ1E
FortinetW32/CoinMiner.ESFJ!tr

How to remove Jaik.101621?

Jaik.101621 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment