Malware

Jaik.63945 (B) removal

Malware Removal

The Jaik.63945 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.63945 (B) virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Jaik.63945 (B)?


File Info:

name: 25E1B5080006053EC997.mlw
path: /opt/CAPEv2/storage/binaries/30f433d2850749f128821ae8b79678ce5303831d046744bbd657ba1c61abe2e1
crc32: 1FAFE354
md5: 25e1b5080006053ec9974233140df436
sha1: 7297da4d6b294d8daee19423ebb6fa7c27ab0290
sha256: 30f433d2850749f128821ae8b79678ce5303831d046744bbd657ba1c61abe2e1
sha512: a2ca868b1e1d70552a80c1dc49ea406688e1166cd789b1be8f39bad667e918feddb6ab667ead4f185d0fceb873039fcbc37129c904f249efefe14e06260e0adc
ssdeep: 384:tQ7ruB+UthhIdi3ZSz+EJxuVczXKSuSHYGSjyc3bcXVYpT0u1GcfQ5sS0rYZ7Gp6:ZPt8dH5JZTKSu7ycEfcfQ+8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197D394387AD55672F37BCEB586F582C7A934B8223D12D50E44DA47860823F19DDB0E1E
sha3_384: 9aa456bbca56146c17ad8d6c0fe8de4dce6f54ba66772a7495d5839bb8e0d70b3f14d91a810f50c8d0f0a8f463f345ed
ep_bytes: 558bec6aff6850300004684019000464
timestamp: 2014-03-17 18:46:26

Version Info:

0: [No Data]

Jaik.63945 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.63945
ClamAVWin.Malware.Upatre-9934559-0
FireEyeGeneric.mg.25e1b5080006053e
McAfeeGeneric-FANY!25E1B5080006
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Waski.Win32.50916
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
AlibabaTrojanDownloader:Win32/Vindor.bb4727ba
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.d6b294
ArcabitTrojan.Jaik.DF9C9
BitDefenderThetaGen:NN.ZexaF.36738.imY@aW34oLh
VirITTrojan.Win32.Upatre.AO
CyrenW32/Upatre.NC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.B
ZonerTrojan.Win32.21752
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Delf.gen
BitDefenderGen:Variant.Jaik.63945
NANO-AntivirusTrojan.Win32.Crypted.cvonkg
AvastWin32:Trojan-gen
TencentTrojan.Win32.Generic.ta
EmsisoftGen:Variant.Jaik.63945 (B)
BaiduWin32.Trojan-Downloader.Waski.l
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader9.48808
VIPREGen:Variant.Jaik.63945
TrendMicroTROJ_GEN.R002C0DIT23
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
Trapminemalicious.high.ml.score
SophosTroj/Wonton-AH
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan/Bublik.gxy
WebrootW32.Trojan.Dropper
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Bublik
Kingsoftmalware.kb.b.995
XcitiumTrojWare.Win32.Bublik.SKI@59ow1o
MicrosoftTrojan:Win32/Vindor!pz
ViRobotTrojan.Win32.Bublik.26112.A
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Downloader/Win.Upatre.R536865
Acronissuspicious
VBA32Trojan.Downloader
ALYacGen:Variant.Jaik.63945
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DIT23
RisingTrojan.Kryptik!1.DBE3 (CLASSIC)
YandexTrojan.GenAsa!kn7uOjKO7pI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.BXKM!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Jaik.63945 (B)?

Jaik.63945 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment