Malware

Jaik.203228 information

Malware Removal

The Jaik.203228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.203228 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.203228?


File Info:

name: 2E7A1529E044C63CC65E.mlw
path: /opt/CAPEv2/storage/binaries/23a23db30bedefb77a4a8a574a1c11ccdc0d25943b43d75ec80d6c1242b67b2a
crc32: 54986A38
md5: 2e7a1529e044c63cc65e03516360996b
sha1: 52f7d1158bf72034be02c4c5ffb311c0f2c475e1
sha256: 23a23db30bedefb77a4a8a574a1c11ccdc0d25943b43d75ec80d6c1242b67b2a
sha512: e8ed0625dad7d25df32f3cc7b90d2f726aec4a16588c0050e67acf44b39a5cfd590db0543b9cf45baca782c5f6c9693fa8a77deaa34903468d414196e3662b15
ssdeep: 98304:TXXDOV5oiABJSYWvlldhj2cC0+dDVX1qUf2TfZ7tVf8R2KwJKK6TK6yLDO3CtRDu:DQDA6YW9lRCHPYUSjZ8RgkfyfOyH8fd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B663345A1481033EFA14A365EED422152AF2D13CEA7BF30BAAC0750DF3B666675B374
sha3_384: 2d9772344f932b9f2c86e3f80d280b6abc38526777c12d89c5e6ea1452c6ccc5cfd1d2ce7998f6e0fceec42d2c8a3da6
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-21 23:24:09

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: MediaBoom team
FileDescription: MediaBoom Setup
FileVersion:
LegalCopyright:
ProductName: MediaBoom
ProductVersion:
Translation: 0x0000 0x04b0

Jaik.203228 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.203228
FireEyeGen:Variant.Jaik.203228
SkyhighBehavesLike.Win32.ObfuscatedPoly.vc
MalwarebytesAdware.DownloadAssistant
AlibabaTrojan:Win32/Ekstak.ca10bca7
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.apuyd
BitDefenderGen:Variant.Jaik.203228
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Ftgl
SophosMal/Generic-S
F-SecureTrojan.TR/Drop.Agent.dhidz
EmsisoftGen:Variant.Jaik.203228 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Ekstak.cihn
AviraTR/Drop.Agent.dhidz
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
ZoneAlarmTrojan.Win32.Ekstak.apuyd
GDataWin32.Trojan.Agent.U3N69F
VaristW32/Ekstak.IU.gen!Eldorado
AhnLab-V3Trojan/Win.DownloadAssistant.R622897
McAfeeArtemis!2E7A1529E044
MAXmalware (ai score=88)
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Jaik.203228?

Jaik.203228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment