Malware

Jaik.49740 (B) malicious file

Malware Removal

The Jaik.49740 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.49740 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Jaik.49740 (B)?


File Info:

name: DE2107C48541F4DFF3F3.mlw
path: /opt/CAPEv2/storage/binaries/06201a97de33d9917d3ed54f9fb7c89eb1c5f6f9fb1174747603ec980ae8783f
crc32: 40097A21
md5: de2107c48541f4dff3f34e0c4fbe44b5
sha1: d96cf77dfaa57d243d70475043d9db0ea6581de9
sha256: 06201a97de33d9917d3ed54f9fb7c89eb1c5f6f9fb1174747603ec980ae8783f
sha512: a5bec9036734a999fdfa980faf742c06bcec493ceefc0becf1c1fcef8bb55fdd7bf4f09bf3cd539d8d358bf147662766966d24416d26fca4287cddac2af55ea9
ssdeep: 49152:7pKD2aC0jH5yr7DWRyZlwH29vjDAk+JpVRlsr:7S24eimwH2R8kSpBQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150758D20E3818139DCF610FE827E66E9256DEE71071414C7239C6EEEAF672E06E34597
sha3_384: 75bd616cada9c7af922a1ff55d8961e1b6a2cc83b4884ad3007678078f80c7747c440d252553d51e605364f3f6997411
ep_bytes: eb05f6a5136e9c50eb056b81db0b11e8
timestamp: 2076-02-17 07:17:43

Version Info:

CompanyName: Piriform Software Ltd
FileDescription: CCleaner Installer
FileVersion: 5.87.0.9306
LegalCopyright: Copyright © 2005-2021 Piriform Software Ltd
ProductName: CCleaner
Translation: 0x0000 0x04b0

Jaik.49740 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.49740
FireEyeGeneric.mg.de2107c48541f4df
K7AntiVirusTrojan ( 0058b4851 )
K7GWTrojan ( 0058b4851 )
Cybereasonmalicious.dfaa57
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CU
APEXMalicious
KasperskyVHO:Trojan-PSW.MSIL.Agent.gen
BitDefenderGen:Variant.Jaik.49740
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazrs5qx8wqLspWQ88VZ8oB80)
Ad-AwareGen:Variant.Jaik.49740
EmsisoftGen:Variant.Jaik.49740 (B)
GDataGen:Variant.Jaik.49740
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.Jr3@aqKyWdhi
ALYacGen:Variant.Jaik.49740
VBA32BScope.Trojan.Packed
CylanceUnsafe
SentinelOneStatic AI – Suspicious PE
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Jaik.49740 (B)?

Jaik.49740 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment