Malware

About “Jaik.38233” infection

Malware Removal

The Jaik.38233 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.38233 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings
  • Interacts with known DarkComet registry keys
  • Generates some ICMP traffic

Related domains:

router.bittorrent.com
router.utorrent.com
i-50.b-000.xyz.bench.utorrent.com
download-lb.utorrent.com

How to determine Jaik.38233?


File Info:

crc32: B3AABEBC
md5: f257a4e79645b6727ac8cd48c80cb3ce
name: F257A4E79645B6727AC8CD48C80CB3CE.mlw
sha1: e4e775ea5cbca89c0f1c362066fcd0042351fdce
sha256: c3c5bcc0cd14d6dbc073e4565edf660d9c377a83dbae49132e9e4c3b526da02d
sha512: c6e31654f6be3348401ab6b56ce16430fb16d462d0b186508cf5fd69842ff1132240368eec27d00271a6cabc8500619db428d23f5da474c925345a63416c800b
ssdeep: 49152:H33Gc5sT5JnTErD26anzFTv4RQUT0PllBVvf8oCTqlNdOcEFfLDDwDq6mXw6+hC:H3LsT5JnTk26anzFTgRQUT0vBVH8oCT
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Jaik.38233 also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Binder.lo77
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.39589
CynetMalicious (score: 100)
CAT-QuickHealVirTool.Vbinder.CO5
ALYacGen:Variant.Jaik.38233
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Binder.100aac03
Cybereasonmalicious.79645b
BaiduWin32.Trojan-Dropper.Binder.m
CyrenW32/Renos.TYAH-0409
SymantecBackdoor.Breut!gm
ESET-NOD32Win32/TrojanDropper.Binder.NBH
APEXMalicious
AvastFileRepMalware
ClamAVWin.Tool.Binder-6750589-0
KasperskyUDS:Trojan-Spy.Win32.Xegumumune
BitDefenderGen:Variant.Jaik.38233
NANO-AntivirusTrojan.Win32.Dwn.sxlhc
ViRobotTrojan.Win32.A.Swisyn.49120[UPX]
MicroWorld-eScanGen:Variant.Jaik.38233
TencentBackdoor.Win32.DarkKomet.zem
Ad-AwareGen:Variant.Jaik.38233
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
BitDefenderThetaAI:Packer.962BFAFE1F
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
FireEyeGeneric.mg.f257a4e79645b672
EmsisoftGen:Variant.Jaik.38233 (B)
SentinelOneStatic AI – Malicious PE
JiangminHackTool.Binder.bh
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan/Generic.ASBOL.C91
MicrosoftBackdoor:Win32/Fynloski.A
GDataGen:Variant.Jaik.38233
AhnLab-V3Trojan/Win32.HackTool.C233787
Acronissuspicious
McAfeeArtemis!F257A4E79645
MAXmalware (ai score=87)
VBA32Binder.Celesty
MalwarebytesTrojan.Binded
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexTrojan.GenAsa!o/ixl7L2Afs
IkarusBackdoor.Win32.Fynloski
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.NBH!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.DarkKomet.HwsBl38A

How to remove Jaik.38233?

Jaik.38233 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment