Malware

Should I remove “Jaik.71684”?

Malware Removal

The Jaik.71684 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.71684 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Jaik.71684?


File Info:

name: 4D74DF1AD5812C83A6CC.mlw
path: /opt/CAPEv2/storage/binaries/4c98928f7700eb21f58ecb3bd4dd82cfd9754d8873259b1e49d70c00e86701a5
crc32: 581B6F29
md5: 4d74df1ad5812c83a6cc3f39839e77f1
sha1: 4d05e42b16717ee041c4251eca15a5fdd4225740
sha256: 4c98928f7700eb21f58ecb3bd4dd82cfd9754d8873259b1e49d70c00e86701a5
sha512: 2d18795b8b8705891291f56552024ded38160ec89c9d121a8ba22ccefbc356a5e985bc0bb33777be65d2f0feebf1e861164a5e108d7274dbf2da296ef0140e12
ssdeep: 393216:pdDfD3pTz1rgnTKjma5gqdH9ZYe7sJqTmAYrA:Lztz9/jmOddak
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BE633B5B240C055F20EA2375C2B46674564A8826CA31B66FB777CC833BC6F47E1EC96
sha3_384: 426791e6b42da98cc3b57db29df7c41b27881d5ea9531e980fc0461c1ec7f7c1650b3553ea3326496114806136f034f7
ep_bytes: b828e995005064ff3500000000648925
timestamp: 2022-02-23 06:20:30

Version Info:

0: [No Data]

Jaik.71684 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.71684
FireEyeGeneric.mg.4d74df1ad5812c83
CylanceUnsafe
K7AntiVirusAdware ( 0050718d1 )
K7GWAdware ( 0050718d1 )
Cybereasonmalicious.b16717
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
BitDefenderGen:Variant.Jaik.71684
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Jaik.71684
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.DownLoader44.44427
ZillyaDownloader.Agent.Win32.468398
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.Win32.Knigsfot
GDataWin32.Trojan.PSE.IA16XK
MAXmalware (ai score=89)
ArcabitTrojan.Jaik.D11804
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win.Reputation.R477827
BitDefenderThetaGen:NN.ZexaF.34638.@lZaaCBPNWob
ALYacGen:Variant.Jaik.71684
VBA32Trojan.Downloader
SentinelOneStatic AI – Malicious PE
AVGWin32:TrojanX-gen [Trj]

How to remove Jaik.71684?

Jaik.71684 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment