Malware

Jaik.50059 removal guide

Malware Removal

The Jaik.50059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.50059 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Argentina)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Jaik.50059?


File Info:

name: 61E9DFFC7349E0ADD3C6.mlw
path: /opt/CAPEv2/storage/binaries/359677817f4ee9302fd195022227d93a892980ac14e935a5b629f28db2a601e6
crc32: 283AE8F0
md5: 61e9dffc7349e0add3c6fb9757ae3343
sha1: e059706f682efc96e3018cfaffb261ff7cd0954b
sha256: 359677817f4ee9302fd195022227d93a892980ac14e935a5b629f28db2a601e6
sha512: 002ffbc55abc47faaa8ddaf335b0f4d63f6be8f6d9c66f6f24565b2662cfa850b6d5d72d0a073bcac41f5cfafcebbb6055b2c07b713c70ca39d1991a50ca8b4c
ssdeep: 49152:2GpppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppL:2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AC67C74AA9FC959F9E307F0A83589C82939FCC29809915BE458374B2DB1E4D4DE132F
sha3_384: 593bd4534a060d9b69b03dc74481720350bafb210efc8d6fce06efde603471814027d116e3abaeb3ebd00d7a85eb5e6c
ep_bytes: e82a5c0000e979feffffcccccccccccc
timestamp: 2021-07-14 11:38:45

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.10.70.17
Translation: 0x0129 0x0794

Jaik.50059 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.50059
FireEyeGeneric.mg.61e9dffc7349e0ad
CAT-QuickHealTrojan.GenericRI.S26298295
McAfeeGenericRXAA-AA!61E9DFFC7349
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3668088
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058cd341 )
AlibabaRansom:Win32/StopCrypt.b3d1e937
K7GWTrojan ( 0058cd341 )
Cybereasonmalicious.f682ef
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNYI
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Jaik.50059
AvastWin32:AceCrypter-B [Cryp]
DrWebTrojan.Siggen16.30516
McAfee-GW-EditionBehavesLike.Win32.Packed.rh
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminExploit.ShellCode.gfi
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.3503976
MicrosoftRansom:Win32/StopCrypt.PAL!MTB
GDataWin32.Trojan.BSE.16VOW5Z
AhnLab-V3Trojan/Win.MalPE.R463520
BitDefenderThetaGen:NN.ZexaF.34182.@tW@aifIwHU
ALYacGen:Variant.Jaik.50059
MAXmalware (ai score=82)
VBA32BScope.Trojan.Convagent
MalwarebytesTrojan.MalPack
RisingTrojan.Kryptik!1.DB29 (RDMK:cmRtazp4mS0qMv+BhPwLA9doeaC4)
YandexTrojan.Kryptik!KEFmNL2tBR0
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:AceCrypter-B [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Jaik.50059?

Jaik.50059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment