Malware

What is “Jaik.195228”?

Malware Removal

The Jaik.195228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.195228 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.195228?


File Info:

name: 5670F0E7E08A90994921.mlw
path: /opt/CAPEv2/storage/binaries/014ed741b83b7bd4572f9fb1285ebecf658b74eb367b712614034c28b9af4845
crc32: D6A6B3D4
md5: 5670f0e7e08a909949216672d3428e66
sha1: 8c8e8e7715e87810ad4d1f943279e081b7fded0e
sha256: 014ed741b83b7bd4572f9fb1285ebecf658b74eb367b712614034c28b9af4845
sha512: ac8ecdffd2991dbcde5eb86eb3525c40c4f1be468c22f03826c39228594764c2e38a7f82ce75537a8e3400d0dc68d674303c51a7ad424fca08c807898e70c28e
ssdeep: 6144:F8LxBspf+q388vnDdsnm0GJPldFNehNTZGbQvtovLZIXahPxCpO2yjP2k5:/p9Dxsm0GJPRNehNtGbQvtoD6Xa6poB5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107742333B5C2C8FBED9181B14268FBF9FB77933819116ECA07A86B13FC529875225125
sha3_384: 191fba8240a57848785a7de763075913e96b577555ef0d94c1615219512dc77a4c722f69bc557f51de937a27b10827db
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:13

Version Info:

0: [No Data]

Jaik.195228 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.195228
FireEyeGeneric.mg.5670f0e7e08a9099
SkyhighBehavesLike.Win32.Generic.fc
ALYacGen:Variant.Jaik.195228
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Agent.Vcho
BitDefenderGen:Variant.Jaik.195228
Cybereasonmalicious.715e87
BitDefenderThetaGen:NN.ZexaF.36792.oyW@a0olDjj
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:Trojan.Win32.Strab
RisingTrojan.Generic@AI.99 (RDML:VUQITMI8NXIZQdL9K5Qzww)
EmsisoftGen:Variant.Jaik.195228 (B)
F-SecureHeuristic.HEUR/AGEN.1337943
VIPREGen:Variant.Jaik.195228
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
MAXmalware (ai score=86)
GoogleDetected
AviraHEUR/AGEN.1337943
VaristW32/Noon.AE.gen!Eldorado
MicrosoftTrojan:Win32/Formbook!ml
GridinsoftTrojan.Win32.FormBook.bot
ArcabitTrojan.Jaik.D2FA9C
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Jaik.195228
CynetMalicious (score: 100)
McAfeeArtemis!5670F0E7E08A
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Suspicious PE
FortinetNSIS/Agent.DCAC!tr
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Jaik.195228?

Jaik.195228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment