Malware

Should I remove “Jaik.50053”?

Malware Removal

The Jaik.50053 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.50053 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Argentina)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Jaik.50053?


File Info:

name: 7C4D78AC9361546D2915.mlw
path: /opt/CAPEv2/storage/binaries/09baf950cee458d08434cdd382a7e4f9aa61099f94b941c687d9e3b6f4d7d0d3
crc32: 19B5018E
md5: 7c4d78ac9361546d2915d9ad17d9de45
sha1: b329a7f0ca46728504167c396ac12dcfb56044a6
sha256: 09baf950cee458d08434cdd382a7e4f9aa61099f94b941c687d9e3b6f4d7d0d3
sha512: f8b78f0b40d0d2d626b88491e15e948ddd9a85caeb6c4bc95ca940c1432265c45d0d5dae0ee652e81d6941b554e48171063170445824fed6017c6c4ba4c26ffd
ssdeep: 49152:AXDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDj:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2C67C04D7A1799EEAF20FF06A758EC63E3B7D929428912E941817DF2FB36015C52327
sha3_384: c85ee4d50fbcb700f8ee4264cb453d534e0d3ddf318695ba1811f7c7ca3c2e988e9ebb7979dce65cc15d9fec37491df1
ep_bytes: e86c480000e979feffffcccccccccccc
timestamp: 2020-10-16 05:01:16

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.70.27
Translation: 0x0129 0x0794

Jaik.50053 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop19.23741
MicroWorld-eScanGen:Variant.Jaik.50053
FireEyeGeneric.mg.7c4d78ac9361546d
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZexaF.34114.@tW@aGfB71Se
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HNXY
ClamAVWin.Malware.Mikey-9917879-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Jaik.50053
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Jaik.50053
EmsisoftGen:Variant.Jaik.50053 (B)
McAfee-GW-EditionBehavesLike.Win32.Packed.wh
SophosML/PE-A + Mal/Agent-AWV
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Jaik.50053
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GEE.C4902249
VBA32BScope.Trojan.Convagent
APEXMalicious
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazqDPXPNFnVsuQUFzpOznSn1)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A

How to remove Jaik.50053?

Jaik.50053 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment