Malware

Jaik.49991 removal tips

Malware Removal

The Jaik.49991 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.49991 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Jaik.49991?


File Info:

name: 08BD428DD88AFA5E12EC.mlw
path: /opt/CAPEv2/storage/binaries/5d9a3a0e619a44db5aca0751a21457e9e678714a5880515787eda9e22802fab2
crc32: BB72005F
md5: 08bd428dd88afa5e12ecc78454f60d89
sha1: f97cbc6703b18053080434de6070aed4de8ce5fe
sha256: 5d9a3a0e619a44db5aca0751a21457e9e678714a5880515787eda9e22802fab2
sha512: 306c93306b1b68673f21af85d666ddc2c63bdacf1bbb6605777369ea7eec618ce0b61cf6a1560b9ecc2bdb8749c91a332f562f5df649f21d506cfe33b0226fe0
ssdeep: 12288:3OvofQeeJZO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7IO7b:KofQ1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CD66AC1A2E25534F1E23E3186754BE44E3BBD52E820955A7230E7CF6BB75C1E90EB12
sha3_384: 10b66e7d78e051e50888810b989626dead68afa75dd57025d6fa28638cd3f3c663cd49fd9b9e08d2f71b71a7077506cd
ep_bytes: e8952b0000e979feffff8bff558bec8b
timestamp: 2021-01-02 12:55:43

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.72.77
Translation: 0x0129 0x07bc

Jaik.49991 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.31749
MicroWorld-eScanGen:Variant.Jaik.49991
FireEyeGeneric.mg.08bd428dd88afa5e
McAfeeLockbit-FSWW!08BD428DD88A
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34114.@xW@auvYw6aK
CyrenW32/Kryptik.FWV.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HNVH
TrendMicro-HouseCallMal_Tofsee
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Jaik.49991
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Jaik.49991
SophosML/PE-A + Mal/Agent-AWV
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Packed.rh
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.fit
MicrosoftRansom:Win32/StopCrypt.PAC!MTB
AhnLab-V3Infostealer/Win.Raccoon.R461522
Acronissuspicious
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingBackdoor.Tofsee!8.1E9 (RDMK:cmRtazr1EWuhn7NoCOeYL5t8b0lY)
YandexTrojan.Kryptik!uFWq23Srw3c
eGambitUnsafe.AI_Score_90%
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A

How to remove Jaik.49991?

Jaik.49991 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment