Malware

About “Jaik.171903” infection

Malware Removal

The Jaik.171903 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.171903 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.171903?


File Info:

name: 46F784F02A0872B6DE91.mlw
path: /opt/CAPEv2/storage/binaries/e0f479127002288798ea762072c81a791aa2abd172fa83aaee8e20b5ddc9e3cd
crc32: 246D5624
md5: 46f784f02a0872b6de9104b6a8bca4fe
sha1: 4b9a48b8ca3c9556eb32d6f1b2dd97a91b8aa03f
sha256: e0f479127002288798ea762072c81a791aa2abd172fa83aaee8e20b5ddc9e3cd
sha512: 8fc911d6865c2fbaf174d705ddef3c2e73f8b1a78ae95b73ee24f00c3c9e3615782db9346f455f3899b57889245f9fab734e843fbdaf7e4c24914e31f6ce4b38
ssdeep: 12288:6FFFbeL4GY02X+1FQOgaF6/SMZoS7qM0FQ:MFCL410akFBga7Mf7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8059E11B6F244F1C615153018FA6736BA78EF4E0B1D9FC34368FD9C79322A2AE3A195
sha3_384: 2de37eb24f22cf56b8a145d9d2a55e89c34524eeb124b4b7a8691636b1eec517003871d5e59972d8ecd74fd59469e51a
ep_bytes: 558bec6aff6898904900687c67450064
timestamp: 2012-03-28 18:13:55

Version Info:

FileVersion: 1.0.1.0
FileDescription: 随风助手之QQ连连看V1.0版(随风QQ:2675297531)
ProductName: 随风助手之QQ连连看V1.0版(随风QQ:2675297531)
ProductVersion: 1.0.1.0
CompanyName: 随风
LegalCopyright: 随风声明: 此软件仅供交流使用。使用者如果违反游戏厂商的相关游戏规定,请使用者自己承担其法律责任与随风本人无关。 随风收徒: 随风收徒,不免费。真心想学习类似于“随风助手”软件,以及其他助手,辅助等等一些“计算机”知识的朋友。请加随风QQ:2675297531(加好友时候,请验证“申请拜师”,因为QQ人数有限,加好友不说明来意的一律不加。) 定制助手: 如果随风的免费助手里面没有您能用到的。可以联系随风,来定制属于您的个性游戏助手。请加随风QQ:2675297531(加好友时候,请验证“定制软件”,因为QQ人数有限,加好友不说明来意的一律不加。) 助手BUG: 如果您发现随风助手存在BUG,请发邮件到“suifengzhushou@qq.com”。Q不处理助手BUG问题。 软件解释权: 关于随风所有助手最终解释权归“随风”本人所有。
Comments: 随风助手之QQ连连看V1.0版(随风QQ:2675297531)
Translation: 0x0804 0x04b0

Jaik.171903 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lQvU
MicroWorld-eScanGen:Variant.Jaik.171903
ClamAVWin.Trojan.Agent-583204
McAfeeArtemis!46F784F02A08
Cylanceunsafe
SangforTrojan.Win32.Agent.Vgc0
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.8ca3c9
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Jaik.171903
AvastWin32:MalwareX-gen [Trj]
EmsisoftGen:Variant.Jaik.171903 (B)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Jaik.171903
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.46f784f02a0872b6
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10S0A6W
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.972
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Jaik.D29F7F
MicrosoftTrojan:Win32/Emotet!ml
GoogleDetected
ALYacGen:Variant.Jaik.171903
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CHV23
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Jaik.171903?

Jaik.171903 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment