Malware

Jaik.42179 (file analysis)

Malware Removal

The Jaik.42179 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.42179 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
lewinckybest30.in

How to determine Jaik.42179?


File Info:

crc32: 04BC201D
md5: d8aebc08f2ca13a241127cf945ac775a
name: D8AEBC08F2CA13A241127CF945AC775A.mlw
sha1: 20e3709a015f7bdf4b686be455d50eb2f612019e
sha256: 24a87fde7ce4b239b6d75f804d24a40bad1f4c9f390afc6fe5911996d2bdced3
sha512: a7db743b748fb79a8348c746251b312121d148eded630ae49d1f7b9721047076f9ac08a935138c1b94a9a50d6874dc1e79ada433655a225d002c6a0fa2c332bd
ssdeep: 768:MgvKwguIzedqSZhNwaEsEunwjkuXEDUXnNymEX7ViLk4qGjxqAf6Zk5kwABkBZJq:MglgTqnCU6kiY7VnGjEAfEfw9ex8HA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Jaik.42179 also known as:

K7AntiVirusTrojan-Downloader ( 0040f2eb1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Zbot.128
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.42179
CylanceUnsafe
ZillyaDropper.Dapato.Win32.11886
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan-Downloader ( 0040f2eb1 )
Cybereasonmalicious.8f2ca1
SymantecTrojan.Ransomlock.G
ESET-NOD32a variant of Win32/Kryptik.AJAX
APEXMalicious
AvastWin32:Kryptik-JLO [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Jaik.42179
NANO-AntivirusTrojan.Win32.Dapato.vdymz
MicroWorld-eScanGen:Variant.Jaik.42179
TencentWin32.Trojan-Dropper.Dapato.debm
Ad-AwareGen:Variant.Jaik.42179
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#2c3yw6z0kr6uc
BitDefenderThetaGen:NN.ZexaF.34266.eqW@a4LjEemi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.30B713
McAfee-GW-EditionPWS-Zbot.gen.bdc
FireEyeGeneric.mg.d8aebc08f2ca13a2
EmsisoftGen:Variant.Jaik.42179 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Dapato.jlu
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.8474B
KingsoftWin32.Troj.Dapato.(kcloud)
MicrosoftTrojanDownloader:Win32/Karagany.L
ArcabitTrojan.Jaik.DA4C3
GDataGen:Variant.Jaik.42179
Acronissuspicious
McAfeePWS-Zbot.gen.bdc
MAXmalware (ai score=85)
VBA32TrojanDropper.Dapato
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.30B713
RisingTrojan.Generic@ML.90 (RDML:Wk+82AM5A3ljkZChajr9Yg)
YandexTrojan.GenAsa!6Ijjs1WkzEw
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.MZ!tr
AVGWin32:Kryptik-JLO [Trj]
Paloaltogeneric.ml

How to remove Jaik.42179?

Jaik.42179 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment