Malware

Should I remove “Jaik.49513”?

Malware Removal

The Jaik.49513 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.49513 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the RedLineDropperAHK malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Created network traffic indicative of malicious activity

Related domains:

iplogger.org
warmbeddy.top

How to determine Jaik.49513?


File Info:

name: 009BF408FF7F26FE650A.mlw
path: /opt/CAPEv2/storage/binaries/2ca801a0f2c52c7a9708070ffbd503366050a4e0ec0f53c9f4faed6cb5aa8f86
crc32: 8AAB591F
md5: 009bf408ff7f26fe650a1306e6b23020
sha1: 0cf56c875d3a3cd52956f2658e23595533b4c564
sha256: 2ca801a0f2c52c7a9708070ffbd503366050a4e0ec0f53c9f4faed6cb5aa8f86
sha512: daf34008dc5202cf7a641de198aca8f36cf23a5f201e6db0d9be4ea25d27f213625557b80f1d0d9f771236722a61f76c2ec5eca765f577943eea5ed7a197abe2
ssdeep: 12288:Y1G7nx1PWHXGQXfjfNsiHRCaPx7ay/QOU2Y5TMqzU1uwX05XNj+K:sGzx1wXGQXfjfpxC2x7ayoOA5RUMXwK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3E4011467A0C034F1B712F459B6A3796A3E79A16728D1CB22C227EE56716F0EF3035B
sha3_384: f93fe0fb08def56900cf7061e6d82dd08039ad540a54187b4180672703b9eab3908ddcc420ab9dceb39a77a712f32db0
ep_bytes: 8bff558bece806030000e8110000005d
timestamp: 2020-08-30 01:41:37

Version Info:

0: [No Data]

Jaik.49513 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.49513
FireEyeGeneric.mg.009bf408ff7f26fe
McAfeeArtemis!009BF408FF7F
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Kryptik.cdb958f6
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.75d3a3
CyrenW32/Kryptik.FQI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKJ
BaiduWin32.Trojan.Kryptik.jm
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Jaik.49513
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Jaik.49513
SophosMal/Generic-R + Troj/Krypt-DY
DrWebTrojan.Siggen15.50435
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Crypt (A)
APEXMalicious
GDataWin32.Trojan.BSE.WS9D4D
JiangminTrojanSpy.Stealer.igz
eGambitUnsafe.AI_Score_94%
AviraTR/Crypt.Agent.ruqsn
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Jaik.DC169
MicrosoftTrojan:Win32/Azorult.RMA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPe.R418715
Acronissuspicious
VBA32BScope.Trojan.Krypter
ALYacGen:Variant.Jaik.49513
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FNWZ!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Jaik.49513?

Jaik.49513 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment