Malware

Should I remove “Jaik.48177”?

Malware Removal

The Jaik.48177 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.48177 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the Vidar malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Attempts to disable Windows Defender
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.48177?


File Info:

name: 1C429F522F47898D603F.mlw
path: /opt/CAPEv2/storage/binaries/9206ef496f748ac2da75ca61d990666da6427a3344d2873a934b9169fb0df75e
crc32: C808E0CA
md5: 1c429f522f47898d603f822325c86a5c
sha1: 264669f60afeb5c8caf7e56cf1a767b7acf172a8
sha256: 9206ef496f748ac2da75ca61d990666da6427a3344d2873a934b9169fb0df75e
sha512: 8ef2202b5ca1b527ce5ac90530c9cbb2cf60bcb90a718790729ecb8d9a9dc00561b04db1998ac62729628a03d65304d90ebd33670c1897b8df17c41ec1b91d42
ssdeep: 49152:xcBiPkZVi7iKiF8cUvFyPVuuU47F/XLgptltokNdzpUmHCFNMx1dk8IAEwJ84vLa:xwri7ixZUvFyPVuuU4hQ/hpgYUXCvLUd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163D53351BFD6C4BBD213213865447F7AF1FAC3D81B2049D377949A0C8F2D9F5802AA9A
sha3_384: 4e58714f6e6d2ff2827cacf3286502527efa1a7ebef18ba424799b69f42582d99f9200193f1dbf2193f97bba4fa5aa44
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Jaik.48177 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.X!c
MicroWorld-eScanGen:Variant.Jaik.48177
CAT-QuickHealTrojan.Jaik
SkyhighBehavesLike.Win32.Generic.vc
ALYacGen:Variant.Jaik.48177
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Jaik.48177
SangforTrojan.Win32.Agent.V23v
K7AntiVirusTrojan ( 0057f23b1 )
BitDefenderGen:Variant.Jaik.48177
K7GWTrojan ( 0057f23b1 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Packed.Barys-9859531-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaRansom:Win32/StopCrypt.6e9
NANO-AntivirusTrojan.Win32.Inject4.ixgvgd
RisingTrojan.Agent!8.B1E (CLOUD)
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1340835
DrWebTrojan.Inject4.13781
TrendMicroTrojan.Win32.CRYPTINJECT.SMC
FireEyeGen:Variant.Jaik.48177
EmsisoftGen:Variant.Jaik.48177 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agentb.kgp
GoogleDetected
AviraHEUR/AGEN.1349608
VaristW32/Kryptik.EQZ.gen!Eldorado
Antiy-AVLTrojan/Win32.Generic
KingsoftWin32.Trojan.Agentb.krec
MicrosoftTrojan:Win32/Azorult!rfn
XcitiumMalware@#n2n9qz0l03v9
ArcabitTrojan.Jaik.DBC31
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataWin64.Trojan.Agent.BBG
CynetMalicious (score: 100)
McAfeeArtemis!1C429F522F47
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Inject
Cylanceunsafe
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderL
TencentWin32.Trojan.Crypt.Ckjl
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HLQQ!tr
BitDefenderThetaGen:NN.ZexaF.36792.ruW@a0Oj6VgG
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Jaik.48177?

Jaik.48177 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment