Malware

How to remove “Jaik.156939”?

Malware Removal

The Jaik.156939 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.156939 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.156939?


File Info:

name: 1AC314AA5F34E420FF3C.mlw
path: /opt/CAPEv2/storage/binaries/cb95a33318717470f7f6db08d20cec2c29f73e9dcc2d3272a22ddabc3104d888
crc32: 89C323C0
md5: 1ac314aa5f34e420ff3c8446e8b01f50
sha1: e9dcee45d57d3b94a1b42790cadb88e7d587a1a9
sha256: cb95a33318717470f7f6db08d20cec2c29f73e9dcc2d3272a22ddabc3104d888
sha512: 734490ab1ab3e213972d9cdb5a1ed8aa1c5d01af4a952888ff2ef6f2f69de58f43b3b22c6e6701e81fdd83801339720f30e192cfaba5c2b273966abb46af910e
ssdeep: 1536:9CgBRbr32ikyVcWhTANqzFzBPGeJFHlJPglyv9mY/AGC+15VMOMRa2uMalIM+ox4:9CgBbkGcuTYYzBOeJFF52Y/AGC+15VMY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17493D0225E11166DC4952F338C48FFACE2182A2B5D7A81D9C7A4BF2D7671E83BD38171
sha3_384: 1cca8639a2419506adb94b923700590b2ceca925bf6770551e176383377e5cd079c028a61056747276eb18267198d141
ep_bytes: 68a80020e6e8f89900009c88242411c9
timestamp: 2013-04-02 03:43:00

Version Info:

Comments:
CompanyName:
FileDescription: DNFPlugin4xp
FileVersion: 2013, 4, 2, 1
InternalName: DNFPlugin4xp
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename: DNFPlugin.EXE
PrivateBuild:
ProductName: DNFPlugin4xp
ProductVersion: 2013, 4, 2, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Jaik.156939 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Jaik.156939
FireEyeGeneric.mg.1ac314aa5f34e420
SangforTrojan.Win32.Save.a
Cybereasonmalicious.5d57d3
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Jaik.156939
EmsisoftGen:Variant.Jaik.156939 (B)
VIPREGen:Variant.Jaik.156939
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
Kingsoftmalware.kb.b.813
XcitiumTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
ArcabitTrojan.Jaik.D2650B
GDataGen:Variant.Jaik.156939
GoogleDetected
BitDefenderThetaAI:Packer.8C62CE811F
ALYacGen:Variant.Jaik.156939
VBA32BScope.TrojanSpy.Keylogger
Cylanceunsafe
RisingTrojan.Generic@AI.98 (RDML:F0DFrbPEKhrP5D26UnN6Sg)
IkarusTrojan-Downloader.Agent
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Jaik.156939?

Jaik.156939 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment