Malware

Jaik.45703 (file analysis)

Malware Removal

The Jaik.45703 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.45703 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

estrix.xyz
ip-api.com
www.facebook.com
limesfile.com
api.faceit.com
connectini.net

How to determine Jaik.45703?


File Info:

crc32: 1E809BB9
md5: 9d5a41bd75da3d05b730222056eab244
name: 9D5A41BD75DA3D05B730222056EAB244.mlw
sha1: 567e41a5259510443a063f001d7bfc25420269f9
sha256: 6552cf64c39a8bd219e97300c065290e11394898334a02f916f58566e2fbc7d7
sha512: 767c2aecb9f97fa1612af868eb5804d08ca0e40a6783cdf4f5a15e8b49f45562d9466f5977ffec123da4e8282957ac2ca6248fb5751f259a084756b99ec11fe1
ssdeep: 98304:t22P3RbOBWvTrinjMUBlAat3HeqMVPnqHhYImN0BbAO:tJZbOUvToMElAat3eqMVQCMP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: King
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Jaik.45703 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e5201 )
DrWebTrojan.Inject4.11771
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.947619
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.30057
SangforTrojan.Win32.CookiesStealer.b
AlibabaTrojanSpy:Win32/CookiesStealer.2a1260a3
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.d75da3
CyrenW32/CookieStealer.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Pswtool-9857488-0
KasperskyTrojan.Win32.CookiesStealer.b
BitDefenderGen:Variant.Jaik.45703
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
MicroWorld-eScanGen:Variant.Jaik.45703
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34690.n88baOE@FOp
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0DEE21
McAfee-GW-EditionBehavesLike.Win32.AdwareWajam.wc
FireEyeGeneric.mg.9d5a41bd75da3d05
EmsisoftGen:Variant.Jaik.45703 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2FFCE3E
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Stealer.KA!MTB
ArcabitTrojan.Jaik.DB287
AegisLabTrojan.Win32.CookiesStealer.4!c
GDataGen:Variant.Graftor.947619
AhnLab-V3Malware/Win.Reputation.C4400382
McAfeeArtemis!9D5A41BD75DA
MAXmalware (ai score=88)
VBA32Trojan.Injector
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R06CC0DEE21
RisingTrojan.IPLogger!1.B69D (CLASSIC:5:U7BTCslyL3J)
YandexRiskware.Unwanted!8s8TPt+ipXw
IkarusTrojan.SuspectCRC
FortinetW32/CoinMiner.CNV!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Jaik.45703?

Jaik.45703 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment