Malware

Should I remove “Jaik.152457 (B)”?

Malware Removal

The Jaik.152457 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.152457 (B) virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.152457 (B)?


File Info:

name: 20EAC65A2B401ADD18C3.mlw
path: /opt/CAPEv2/storage/binaries/d0389aa09313fc484e87825cf0449961586e71425d4e4c30e5a28b0b78c8367d
crc32: 79D7AD97
md5: 20eac65a2b401add18c33f351316258d
sha1: f4547080513a59cb14589040d94109bbe0e406c0
sha256: d0389aa09313fc484e87825cf0449961586e71425d4e4c30e5a28b0b78c8367d
sha512: 173f42e107a786626fc97fefd954a019a5845e8925e83e3aad5dca8565e340e9cda2b273cd9359e4ca4d2bcd4ccdd25eca1534c901667a8634ca1ef98aa8fdcd
ssdeep: 49152:2d0/o7S2aQBXoljXaS3TdpwzmF+X/qe/jjkT67qu9tWUNZ:2+Q7S2aQKn5pDF+Q67
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125C5BF26BB4D9472D1B25031721DE76705A875321F6A50C7F3C4AF2E29E06D2FA3AE07
sha3_384: 835789a14aaa8fc1682c1f670679e3635cdb5ff892cfe9d4c5590073e7dc00689550c185cfd00130bc55edcaf8890ee4
ep_bytes: e8c2040000e980feffff558bec5156ff
timestamp: 2018-08-11 23:20:46

Version Info:

0: [No Data]

Jaik.152457 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Adload.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.152457
ClamAVWin.Malware.Softcnapp-6787524-0
FireEyeGeneric.mg.20eac65a2b401add
CAT-QuickHealTrojan.Skeeyah.S3293683
McAfeeSoftcnapp
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Jaik.152457
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005631a71 )
AlibabaMalware:Win32/km_2ec7ff6.None
K7GWAdware ( 005631a71 )
Cybereasonmalicious.0513a5
BitDefenderThetaGen:NN.ZexaF.36350.MAW@a4qnsXlj
CyrenW32/S-2a1c663c!Eldorado
SymantecPUA.Downloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Jaik.152457
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Generic.h
EmsisoftGen:Variant.Jaik.152457 (B)
F-SecureHeuristic.HEUR/AGEN.1319114
DrWebAdware.Softcnapp.92
TrendMicroTROJ_GEN.R002C0PHA23
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosSoftcnapp (PUA)
IkarusPUA.Softcnapp
GDataGen:Variant.Jaik.152457
JiangminTrojan.Generic.cnqnc
AviraHEUR/AGEN.1319114
Antiy-AVLGrayWare/Win32.Softcnapp
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ArcabitTrojan.Jaik.D25389
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftPUA:Win32/Softcnapp
GoogleDetected
AhnLab-V3PUP/Win32.Helper.R233980
VBA32BScope.Adware.Puwaders
ALYacGen:Variant.Jaik.152457
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PHA23
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!BLwohnTxrUM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Softcnapp
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Jaik.152457 (B)?

Jaik.152457 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment