Malware

Should I remove “Jaik.283”?

Malware Removal

The Jaik.283 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.283 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

my.oplay.pw

How to determine Jaik.283?


File Info:

crc32: F6B3F45B
md5: b58061749be22a731826ef0f43c756b6
name: B58061749BE22A731826EF0F43C756B6.mlw
sha1: dcc063c60ab0ce98cb9dd628a7f31675c4c142e2
sha256: f272fddc2cf1bc470c30aa5a40714854941d8981a092410c109d7183b8ac34ce
sha512: 696a6c79b621257bd4d6d42873d3225caa544628079d26fd21d9ff73eb99a5ef86e358de95b8da0e4f50b2c9439a9b74dcc37dfc44af618331fb01bc52ab0eec
ssdeep: 3072:mHmo8lBJDDZYsj6WrG4fAitI5/CDqtvqQUKnn:mHmo8lBJGsPGEAit4hUS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CSRSS.Exe
FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.19041.546
FileDescription: Client Server Runtime Process
OriginalFilename: CSRSS.Exe
Translation: 0x0409 0x04b0

Jaik.283 also known as:

K7AntiVirusTrojan ( 004639e71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.58945
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5244236
ALYacGen:Variant.Jaik.283
CylanceUnsafe
ZillyaTrojan.Mucc.Win32.16
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004639e71 )
Cybereasonmalicious.49be22
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.QKO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Mucc.pf
BitDefenderGen:Variant.Jaik.283
MicroWorld-eScanGen:Variant.Jaik.283
TencentMalware.Win32.Gencirc.10b7d549
Ad-AwareGen:Variant.Jaik.283
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZexaF.34692.iC1@ay7Ubdoi
TrendMicroBKDR_ZEGOST.SM39
McAfee-GW-EditionGenericRXEK-UO!B58061749BE2
FireEyeGen:Variant.Jaik.283
EmsisoftGen:Variant.Jaik.283 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Mucc.ak
AviraHEUR/AGEN.1134705
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.203834F
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Gen.cc!s1
GDataGen:Variant.Jaik.283
McAfeeGenericRXEK-UO!B58061749BE2
MAXmalware (ai score=81)
VBA32BScope.Trojan.Agent
MalwarebytesBackdoor.Farfli
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM39
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazqo+dTs+cEk26a9C34iU6fE)
YandexTrojan.GenAsa!TJge4UKNGAs
IkarusTrojan.Win32.Redosdru
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Farfli.AIL!tr
AVGWin32:Malware-gen

How to remove Jaik.283?

Jaik.283 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment